ci4-cms-erp/ci4ms
Modular CodeIgniter 4 CMS featuring RBAC admin, theming, blog/page management, elFinder media integration, and CLI tooling for rapid customization.
Activity
- Latest release
- 1mo ago
- Total releases
- 65
- Cadence
- ~2 days
- Last 12 months
- 25
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Nov 06, 2023
| Version | Released | |
|---|---|---|
0.35.0.0
minor
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev |
0.35.0.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.34.1.0
patch
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev |
0.34.1.0
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.34.0.0
minor
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev |
0.34.0.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.33.2.0
patch
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev |
0.33.2.0
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.33.1.0
minor
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.32.0.0
minor
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.11.0
patch
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.10.0
patch
1 CVE
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev |
0.31.10.0
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.31.9
patch
4 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.8.0
patch
4 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev |
0.31.8.0
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.31.7.0
patch
6 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41890
GHSA-vgrf-pr28-vf98
May 04, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Medium
Network
Low
High
None
SummaryThe The This is a real bug even within the admin trust model: the action should be scoped to the theme's own tables. The permission grants delete this theme's data", not "drop any table". DetailsLocation
Vulnerable Code
PoC
Impact
Additional noteQuick note on the design intent for deleteProcess — I noticed delete_confirm.php scopes the checkboxes to the theme's own migration files, and the CHANGELOG confirms the selective deletion was intentional (admins can choose which tables to keep). The server-side deleteProcess already has all the information it needs to validate the input — deleteConfirm derives the valid table set from the migration files, deleteProcess just needs to do the same before acting on the POST. Happy to clarify if useful. Affected versions
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev |
0.31.7.0
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.31.6.0
patch
7 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41890
GHSA-vgrf-pr28-vf98
May 04, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Medium
Network
Low
High
None
SummaryThe The This is a real bug even within the admin trust model: the action should be scoped to the theme's own tables. The permission grants delete this theme's data", not "drop any table". DetailsLocation
Vulnerable Code
PoC
Impact
Additional noteQuick note on the design intent for deleteProcess — I noticed delete_confirm.php scopes the checkboxes to the theme's own migration files, and the CHANGELOG confirms the selective deletion was intentional (admins can choose which tables to keep). The server-side deleteProcess already has all the information it needs to validate the input — deleteConfirm derives the valid table set from the migration files, deleteProcess just needs to do the same before acting on the POST. Happy to clarify if useful. Affected versions
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.5.0
patch
7 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41890
GHSA-vgrf-pr28-vf98
May 04, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Medium
Network
Low
High
None
SummaryThe The This is a real bug even within the admin trust model: the action should be scoped to the theme's own tables. The permission grants delete this theme's data", not "drop any table". DetailsLocation
Vulnerable Code
PoC
Impact
Additional noteQuick note on the design intent for deleteProcess — I noticed delete_confirm.php scopes the checkboxes to the theme's own migration files, and the CHANGELOG confirms the selective deletion was intentional (admins can choose which tables to keep). The server-side deleteProcess already has all the information it needs to validate the input — deleteConfirm derives the valid table set from the migration files, deleteProcess just needs to do the same before acting on the POST. Happy to clarify if useful. Affected versions
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.4.0
patch
10 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41890
GHSA-vgrf-pr28-vf98
May 04, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Medium
Network
Low
High
None
SummaryThe The This is a real bug even within the admin trust model: the action should be scoped to the theme's own tables. The permission grants delete this theme's data", not "drop any table". DetailsLocation
Vulnerable Code
PoC
Impact
Additional noteQuick note on the design intent for deleteProcess — I noticed delete_confirm.php scopes the checkboxes to the theme's own migration files, and the CHANGELOG confirms the selective deletion was intentional (admins can choose which tables to keep). The server-side deleteProcess already has all the information it needs to validate the input — deleteConfirm derives the valid table set from the migration files, deleteProcess just needs to do the same before acting on the POST. Happy to clarify if useful. Affected versions
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.3.0
patch
16 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41890
GHSA-vgrf-pr28-vf98
May 04, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Medium
Network
Low
High
None
SummaryThe The This is a real bug even within the admin trust model: the action should be scoped to the theme's own tables. The permission grants delete this theme's data", not "drop any table". DetailsLocation
Vulnerable Code
PoC
Impact
Additional noteQuick note on the design intent for deleteProcess — I noticed delete_confirm.php scopes the checkboxes to the theme's own migration files, and the CHANGELOG confirms the selective deletion was intentional (admins can choose which tables to keep). The server-side deleteProcess already has all the information it needs to validate the input — deleteConfirm derives the valid table set from the migration files, deleteProcess just needs to do the same before acting on the POST. Happy to clarify if useful. Affected versions
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.2.0
patch
16 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41890
GHSA-vgrf-pr28-vf98
May 04, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Medium
Network
Low
High
None
SummaryThe The This is a real bug even within the admin trust model: the action should be scoped to the theme's own tables. The permission grants delete this theme's data", not "drop any table". DetailsLocation
Vulnerable Code
PoC
Impact
Additional noteQuick note on the design intent for deleteProcess — I noticed delete_confirm.php scopes the checkboxes to the theme's own migration files, and the CHANGELOG confirms the selective deletion was intentional (admins can choose which tables to keep). The server-side deleteProcess already has all the information it needs to validate the input — deleteConfirm derives the valid table set from the migration files, deleteProcess just needs to do the same before acting on the POST. Happy to clarify if useful. Affected versions
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.1.0
patch
17 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41890
GHSA-vgrf-pr28-vf98
May 04, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Medium
Network
Low
High
None
SummaryThe The This is a real bug even within the admin trust model: the action should be scoped to the theme's own tables. The permission grants delete this theme's data", not "drop any table". DetailsLocation
Vulnerable Code
PoC
Impact
Additional noteQuick note on the design intent for deleteProcess — I noticed delete_confirm.php scopes the checkboxes to the theme's own migration files, and the CHANGELOG confirms the selective deletion was intentional (admins can choose which tables to keep). The server-side deleteProcess already has all the information it needs to validate the input — deleteConfirm derives the valid table set from the migration files, deleteProcess just needs to do the same before acting on the POST. Happy to clarify if useful. Affected versions
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.31.0.0
minor
16 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.28.6.0
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev |
0.28.6.0
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.28.5.0
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev | ||
0.28.4.0
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.28.3.0
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.28.3.0
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.28.0.0
minor
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.27.0.0
minor
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.27.0.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.26.3.4
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.26.3.4
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.26.3.3
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.26.3.3
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.26.3.2
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.26.3.1
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.26.3.0
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.26.2.0
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.26.2.0
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.26.1.0
patch
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.26.0.0
minor
35 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41891
GHSA-5hfv-c864-qcq9
May 04, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Medium
Network
Low
Low
None
SummaryThe auth filter has the deactivated/banned user check commented out. DetailsCodeIgniter Shield's
EvidenceImpact
Additional noteThe commented-out block appears to be a deferred placeholder — it was written but disabled from the very first commit that introduced the filter, and has never been active. The later addition of SessionTracker (v0.31.4.0) suggests the dev was aware of the session revocation gap, but account-level deactivation (users.active = 0) remains unenforced. Could you verify if this is intentionally pending or simply forgotten and not documented?. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 10 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
Fixed in
0.31.8.0
References
Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41587
GHSA-fw49-9xq4-gmx6
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
Network
Low
High
None
SummaryA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. DetailsFile: After a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52 File: The helper copies every file matching . from Because the web root is PHP files are also installed — without filtering — into app/Controllers/templates//, app/Libraries/templates//, and other app/ subdirectories: The theme name is derived from the uploaded filename via PoCPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload). Step 1 — Build the malicious ZIP:
Step 2 — Upload:
Step 3 — Execute:
Expected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)). ImpactType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root. Who is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise. Affected versions
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
+ 9 more Show less
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
Fixed in
0.31.7.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.3.0
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.2.0
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.1.0
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.0.43
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.0.39
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.0.30
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.0.2
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.0.1
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.25.0.0
minor
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.24.0.60
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.24.0.60
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.24.0.45
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.24.0.42
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.24.0.27
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.24.0.20
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.24.0.19
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.24.0.18
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev | ||
0.24.0.16
patch
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.24.0.16
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.24.0.0
minor
33 CVEs
CVE-2026-45270
GHSA-gqr2-7hcg-rchf
May 18, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
SummaryThe DetailsThis is a sibling-module variant of the same root cause as the Blog stored-XSS issue. The
CodeIgniter 4's Pages controller —
The row lands in
This is distinct from the Blog finding:
Routes are confirmed protected by PoCPrerequisite: an account with the Step 1 — log in to backend, capture cookies:
Step 2 — create a page with a malicious
Expected: redirect to Step 3 — trigger the XSS by visiting the public URL:
Step 4 — broaden blast radius (optional, requires
After this, the malicious page is served at Impact
Recommended FixStop relying on the broken reference-mutation pattern. The simplest, safest fix is to call the existing
Apply the same pattern in every other module that uses Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45139
GHSA-245j-xjvr-xvm5
May 18, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
SummaryThe Fileeditor module enforces an extension allowlist ( DetailsRoot cause: inconsistent application of the extension allowlist across Fileeditor operations in The class declares an allowlist used by content-write operations:
The validation gauntlet a path traverses before reaching
Critical CodeIgniter 4 framework files (
The recent security patch in commit Authorization is provided by the PoCPrerequisites: an authenticated session with
Trace verifying the validation logic for
ImpactA backend user holding the Fileeditor
The destructive surface exceeds Fileeditor's intended capability: the saveFile/createFile allowlist signals an explicit design intent to restrict modifications to safe content extensions, yet delete/rename can target arbitrary file types. Even where the actor is already a superadmin, the bug widens the destructive blast radius beyond what the editor UI exposes and beyond what The path is gated by an admin-tier permission, so PR:H is honest; impact is limited to integrity/availability of files reachable by the web server user. Recommended FixApply the same
Stronger hardening — and aligned with the editor's apparent intent — is to confine all Fileeditor operations to a directory allowlist (e.g. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-45138
GHSA-2m69-jmvh-6chr
May 18, 2026
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryThe custom DetailsRoot cause: by-reference mutation never propagates
CI4's validator invokes the rule via a local variable
The reference mutation modifies that local Sink: raw POST is persisted and rendered unescapedThe Blog controller takes
The same pattern is used in The public blog post template echoes the field with no escaping:
The view is reached through Trust boundaryBackend routes ( Same defect in the Pages moduleA previous Stored XSS in the Pages module was "fixed" by introducing the very PoCPrerequisite: any account holding the backend
Independent root-cause verification (run against the local app):
That is, when the same payload is fed to the real CI4 validator with the project's rule set, Impact
Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 45 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
Fixed in
0.31.9.0
References Updated May 18, 2026 · Source: OSV.dev
CVE-2026-41203
GHSA-xv3r-vr59-95rg
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Theme/Controllers/Theme.php:13-56 implements the theme upload action. ZipArchive::extractTo() is called directly with no iteration over entry names to verify they resolve inside the destination:
A ZIP containing entries like Routing: modules/Theme/Config/Routes.php binds A companion Zip Slip bug in Backup::restore is tracked separately as GHSA-xp9f-pvvc-57p4. PoCBuild the archive:
Upload through the Theme manager with an authenticated session that has theme create:
Trigger the shell:
ImpactAny ci4ms account that can upload a theme can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41202
GHSA-xp9f-pvvc-57p4
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
Network
Low
Low
None
Summaryci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. Detailsmodules/Backup/Controllers/Backup.php:80-119 implements the restore action. The uploaded file is moved to
A ZIP containing entries like Routing: modules/Backup/Config/Routes.php binds PoCBuild the archive:
Submit it as a backup to restore:
Trigger the shell:
ImpactAny ci4ms account that can restore a backup can write arbitrary files under the application root and gain remote code execution on the server, fully compromising the installation, the database credentials stored in .env, and any content the site handles. Because the route is in the csrfExcept list, a logged-in administrator who visits a malicious page can be forced to perform the restore cross-site, turning this into drive-by RCE against site operators. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-41201
GHSA-qxpq-82f3-xj47
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
An attacker can achieve Full Account Takeover and Privilege Escalation via Stored DOM XSS in the backup module's filename field, which is manipulated through an SQL file that tampers with the filename field to contain a hidden XSS payload. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 40 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
0.31.4.0
Fixed in
0.31.5.0
References Updated May 08, 2026 · Source: OSV.dev
CVE-2026-39394
GHSA-vfhx-5459-qhqh
Apr 08, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe DetailsIn
This value is passed to
Since the The Access conditions:
Mitigation note: PoCScenario: Application is deployed but cache has expired (or fresh install window).
Expected result: The
These injected lines override the legitimate CSRF exploitation variant (no direct access needed):
ImpactAn unauthenticated attacker can inject arbitrary configuration into the
The attack is amplified by the absence of CSRF protection on the install endpoint, allowing exploitation via a malicious webpage visited by anyone on the same network. Recommended Fix
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39393
GHSA-8rh5-4mvx-xj7j
Apr 08, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe install route guard in ci4ms relies solely on a volatile cache check ( DetailsThe
This requires both conditions —
When the database is unreachable (connection failure, timeout, maintenance), the The install controller at
Additionally, CSRF protection is explicitly disabled for all install routes in
The cache has a 24-hour TTL ( PoCPrerequisites: The target database must be temporarily unreachable (maintenance window, connection exhaustion, network partition) at a moment when the
ImpactWhen exploited during a database outage coinciding with cache expiry:
The attack requires no authentication, no CSRF token, and no user interaction. The exploitability window recurs every 24 hours at cache TTL expiry and after any admin action that clears the settings cache, but is only exploitable when the database is simultaneously unreachable. Recommended FixReplace the volatile cache-based install guard with a persistent filesystem lock:
Create the lock file at the end of successful installation in
Additionally, add validation for the
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39392
GHSA-fjpj-6qcq-6pw2
Apr 08, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Pages module does not apply the DetailsThe Blog module correctly applies HTMLPurifier sanitization to content fields:
The Pages module omits this rule in both create and update methods:
Content is stored directly without sanitization:
On the public frontend, the content is rendered as raw HTML without escaping:
Note that the same template correctly escapes the title field on line 9 using The PoCStep 1: Create a page with XSS payload (requires admin session)
Step 2: Visit the page as any unauthenticated user
Expected result: The Impact
The attack requires admin-level authentication (PR:H), but the impact crosses the security boundary to affect all unauthenticated public visitors (S:C). In a multi-admin CMS environment, a lower-privileged admin with only page-editing permissions could compromise higher-privileged admin sessions. Recommended FixAdd the
to:
Additionally, as defense-in-depth, escape content output in the view template or use the existing Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39391
GHSA-7cm9-v848-cfh2
Apr 08, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
SummaryThe blacklist (ban) note parameter in DetailsIn
Shield's
In the
The HTML string is returned as JSON (line 90) and DataTables renders it into the DOM. CSP is disabled ( PoCStep 1 — Store XSS payload via ban endpoint:
Expected response: Step 2 — Trigger payload:
Any admin navigating to
The XSS fires when the admin hovers over the blacklist button for the banned user. Alternative immediate-execution payload:
Impact
Recommended FixWrap
Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39390
GHSA-x3hr-cp7x-44r2
Apr 08, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
5.5
/ 10
Medium
Network
Low
High
None
Changed
Low
Low
None
SummaryThe Google Maps iframe setting ( DetailsInput sanitization (
The three regex patterns only match attributes beginning with Output rendering (
The output applies Why HTML entities bypass Why this is same-origin: Per the HTML specification, an PoCPrerequisites: Authenticated admin session with Step 1: Inject the payload
The
Step 2: Visit any public page that includes the Google Maps widget Navigate to the frontend contact or footer page as an unauthenticated visitor. The browser renders the Expected result: JavaScript Cookie theft variant:
Impact
The attack requires a compromised or malicious admin account with settings update permission. While this is a privileged starting point (PR:H), the impact crosses to all unauthenticated visitors (S:C), justifying Medium severity. Recommended FixReplace the regex-based attribute blocklist with a strict allowlist approach. Only allow
This allowlist approach ensures that dangerous attributes like Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-39389
GHSA-9rxp-f27p-wv3h
Apr 08, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
High
High
Low
SummaryThe Fileeditor controller defines a DetailsThe
This array is checked only in
However,
This means any file within ROOTPATH — regardless of extension ( Similarly,
Compounding factor: CSRF protection is disabled for all fileeditor routes in
This means the write and delete operations are additionally vulnerable to cross-site request forgery if an authenticated user visits a malicious page. PoCRequires an authenticated backend session with Step 1: Read .env file to extract secrets
Expected response: JSON containing Step 2: Read PHP configuration files
Expected response: Full database configuration PHP source with credentials (note: Step 3: Overwrite composer.json for RCE (requires
The next Step 4: Delete .env (requires
Impact
Recommended FixApply
Also re-enable CSRF protection by removing the CSRF exemption in Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 39 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.2.0
0.31.3.0
Fixed in
0.31.4.0
References Updated Apr 08, 2026 · Source: OSV.dev
CVE-2026-35035
GHSA-5ghq-42rg-769x
Apr 06, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 37 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
Fixed in
0.31.2.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34989
GHSA-vr2g-rhm5-q4jr
Apr 03, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
Network
Low
Low
None
SummaryVulnerability 1: Stored DOM XSS via Profile Name Update (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint: Vulnerability 2: Stored XSS via User Name Rendering Across Multiple Endpoints (Privilege Escalation)(Required for the chain)
DescriptionUser-controlled profile fields (specifically the username / full name) are rendered unsafely across multiple application endpoints, including administrative and content-related interfaces. The application fails to apply proper output encoding when displaying these values. When an administrator accesses affected pages, the stored XSS payload executes in the administrator’s browser context, resulting in administrative privilege escalation and potential full admin account takeover. This issue is not limited to a single endpoint and affects all areas where the username is rendered, including but not limited to:
Attack Scenario
Impact
Endpoint Example: Steps To Reproduce (POC)
Recommended Remediation
Ready Video POC:https://mega.nz/file/iEVEyT4Y#f046o6ZwYBfS1kK0HNKOCFm6tL_8_SbLtWWKC1hYC4M Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 53 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
0.31.0.0
0.31.1.0
0.31.10.0
0.31.11.0
0.31.2.0
0.31.3.0
0.31.4.0
0.31.5.0
0.31.6.0
0.31.7.0
0.31.8.0
0.31.9
0.32.0.0
0.33.1.0
0.33.2.0
0.34.0.0
0.34.1.0
0.35.0.0
Fixed in
31.0.0.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34572
GHSA-8fq3-c5w3-pj3q
Apr 01, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deactivation (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/zJkhwCII#G1-TecKmNBJmEeBS0ExsAY_RXEmAl3QqMqu4t5oy844 Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34571
GHSA-fc4p-p49v-r948
Apr 01, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA critical Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. DetailsThe vulnerability resides in the backend user creation feature accessible via:
User-supplied input in the name and surname fields is stored without proper validation or sanitization. When this data is later rendered in the backend users listing page, it is injected directly into the HTML without output encoding. Because of this, attackers can embed malicious JavaScript payloads that execute in the context of authenticated backend users. This indicates missing contextual output escaping (e.g., HTML encoding) and insufficient input sanitization, leading to persistent script execution. The vulnerability is particularly severe because:
PoCSteps to reproduce:
ImpactSeverity: Critical This vulnerability enables:
Since the payload executes automatically without user interaction once stored, exploitation requires minimal effort and can impact all backend users. Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34570
GHSA-4vxv-4xq4-p84h
Apr 01, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryVulnerability: Improper Session Invalidation on Account Deletion (Broken Access Control / Logic Flaw)
DescriptionThe application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. Affected Functionality
Attack Scenario
Impact
Endpoint Example: Any endpoint accessible to authenticated users, including dashboards, administrative interfaces, user management pages, and API endpoints. Steps To Reproduce (PoC)
Remediation
Ready Video POC:https://mega.nz/file/7dlUTQAB#0oXOapF5XYN4DRRG1xYj6DajmuP72MpMdsHqbVBMmWw Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34569
GHSA-fhrf-q333-82fm
Apr 01, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via Blog Category Title (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. This stored payload is later rendered unsafely across public-facing blog category pages, administrative interfaces, and blog post views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GAFC3AJY#3LHyuyl7I7921UEeA-JlUYdckh6zGLCTy-6w9BNzSmQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34568
GHSA-x7wh-g25g-53vg
Apr 01, 2026
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Post Content (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. This stored payload is later rendered unsafely in multiple application views without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/bYtCQRqT#ph1S_01XaYXiNTzanP3AVL6aQMe0YC5Py7Gko1FoT4A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34567
GHSA-r33w-c82v-x5v7
Apr 01, 2026
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. This stored payload is later rendered unsafely when the Categories are viewed via blog posts, without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/SAdVxK7b#kFW_sFOim_d_1AnVcpwvzOEV4MHv33LLooL4Xa_Ymgg Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34566
GHSA-458r-h248-29c5
Apr 01, 2026
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Page Management Fields (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. These stored values are later rendered without proper output encoding across administrative page lists and public-facing page views, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Affected Fields
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/iAkWAKQY#hCUv4DlMPFykPvb4gO94ZVGj64tpUk99gLxE6u1kASk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34565
GHSA-xgh5-w62m-8mpr
Apr 01, 2026
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Posts Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PcMiUA5K#L2RlZJa340Q8K42TksxiXMuo_9XsRYPi14-WvBnak2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34564
GHSA-g4pp-fhgf-8653
Apr 01, 2026
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Pages Added to Menu (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoint:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/2c8lHSBQ#vwFDj0vhq7vLwMJjBjnAgbHWiIdFqUxAA913H_yQExQ Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34563
GHSA-85m8-g393-jcxf
Apr 01, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryVulnerability: Stored DOM Blind XSS via Backup Management Filename (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34562
GHSA-v897-c6vq-6cr3
Apr 01, 2026
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
SummaryVulnerability: Stored DOM XSS via System Settings – Company Information (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Affected fields include, but are not limited to:
Unlike the public-facing landing page injection vulnerability, this issue executes directly on the same settings page. The injected payload breaks out of the HTML attribute context and is immediately interpreted by the browser when rendered, resulting in same-page DOM-based stored XSS. This represents different functionality and a separate vulnerability from public-facing rendering. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/qEcFUIjR#2OKX78JgPQI2x5957GE-vx1zYzJv2a9JqjyBsrRFBkk Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34561
GHSA-gcfj-cf7j-vwgj
Apr 01, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Social Media Management (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configuration fields, including Social Media and Social Media Link, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike typical stored XSS that executes on other pages (such as public-facing landing pages), this vulnerability executes directly on the same settings page. The injected payload breaks out of the input attribute context and is immediately interpreted by the browser, resulting in same-page DOM-based XSS. This represents a different functionality and a separate vulnerability class from public-facing landing page injection. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/PBEFBCpJ#rGGxjnPN38qDtmJssAgIoLuStBcQaZFpR0J1bKAXApc Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34560
GHSA-r4v5-rwr2-q7r4
Apr 01, 2026
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM Blind XSS via Logs Interface Rendering (Administrative Context Execution)
DescriptionThe application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. For example, accessing When an administrator views the logs page, the stored payload executes automatically in the administrative browser context, leading to stored blind cross-site scripting (Blind XSS). Affected Functionality
Attack Scenario
Any method or endpoint that logs user-controlled input without sanitization will result in the same Blind XSS condition when viewed inside logs management. Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/jRN3nDSR#wJCwyFhbeT-OYAwlaTD_7j6wc5wRgz1EGJL0bnuhHxY Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34559
GHSA-4333-387x-w245
Apr 01, 2026
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Blog Tag Name (Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. This stored payload is later rendered unsafely across public tag pages and administrative interfaces without proper output encoding, leading to stored cross-site scripting (XSS). Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/GI9Bnbha#FkVY4K7AiuttnBGDFaCtxuJwKk-afRcKjYJnkqfLZOM Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 06, 2026 · Source: OSV.dev
CVE-2026-34557
GHSA-rpjr-985c-qhvm
Apr 01, 2026
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Group / Role Management Fields (Administrative Context Execution)
DescriptionThe application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side. These stored payloads are later rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/6QUEXDbR#JXzYXg9bef_NeSUVFB4R03UeXLtAVtYwTRsdrHLlokU Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-34558
GHSA-v77r-xg3p-75g7
Apr 01, 2026
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryVulnerability: Stored DOM XSS via Methods Management Fields (Global Persistent Payload Execution)
DescriptionThe application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). Critically, because created methods are automatically rendered inside the system’s navigation/menu structure, the injected payload executes globally — meaning every page visited where the malicious method appears in the menu triggers the XSS payload automatically. This significantly increases severity, as exploitation is not limited to a single view — it becomes a platform-wide persistent execution point. Affected Functionality
Affected FieldsThe following fields accept unsanitized input and allow persistent JavaScript injection:
Attack Scenario
Because the navigation is globally rendered across backend pages, the XSS triggers on nearly every administrative page visit. Impact
This vulnerability is highly severe due to:
Endpoints:
Steps To Reproduce (POC)
Remediation
Failure to properly encode and sanitize user-controlled method fields results in full application compromise through persistent global XSS. Ready Video POC:https://mega.nz/file/CFsiQAJS#cBSF2lCMD7YNZEKYEjw3T8YturY92oBvrdRQ08gmw2A Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated Apr 01, 2026 · Source: OSV.dev
CVE-2026-27599
GHSA-66m2-v9v9-95c3
Mar 30, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryVulnerability: Stored DOM XSS via System Settings – Mail Settings (Same-Page Attribute Breakout & Persistent Payload Injection)
DescriptionThe application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. Unlike public-facing XSS that executes on landing pages, this vulnerability executes immediately on the same settings page. The injected payload breaks out of the HTML attribute context and is interpreted by the browser when rendered, resulting in same-page DOM-based XSS. This represents different functionality and a separate vulnerability from landing-page injection. Example Affected Fields
Affected Functionality
Attack Scenario
Impact
Endpoints:
Steps To Reproduce (POC)
Remediation
Ready Video POC:https://mega.nz/file/KRNhUI6Q#NGC3Bow3RlnmdU1H2bGu1BGbpfIc-awi6IlvTp08V1s Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 35 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
0.28.5.0
0.28.6.0
Fixed in
0.31.0.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25510
GHSA-gp56-f67f-m4px
Feb 02, 2026
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Summary A critical vulnerability has been identified in CI4MS that allows an authenticated user with file editor permissions to achieve Remote Code Execution (RCE). By leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. Vulnerability Details The vulnerability exists in the /backend/fileeditor/createFile and /backend/fileeditor/save API endpoints. Unrestricted File Creation: The createFile endpoint allows users to create files with any extension (including .php) in web-accessible directories such as /public. Arbitrary Content Injection: The save endpoint allows users to write arbitrary content into the created files without sufficient server-side validation or sanitization. An attacker can combine these two flaws to create a PHP webshell and execute system-level commands, leading to a complete compromise of the web server. Impact Successful exploitation allows: Full access to the server's file system and databases. Execution of arbitrary OS commands. Permanent modification or deletion of application data. Steps to Reproduce Log in to an account with permissions to use the file editor. Create a new PHP file in a public directory using the following request:
Inject a PHP payload into the file using the save endpoint:
Access the file via the browser to execute commands: https://[SERVER_URL]/exploit.php?cmd=whoami Suggested Mitigation Path Validation: Restrict file operations to non-executable directories. Extension Whitelisting: Strictly allow only safe file extensions (e.g., .css, .js, .txt) and block executable extensions like .php, .phtml, etc. Content Sanitization: Implement server-side checks to prevent the injection of malicious code patterns. Execution Prevention: Disable PHP execution in public/upload directories via server configuration (e.g., .htaccess or Nginx config). Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2026-25509
GHSA-654x-9q7r-g966
Feb 02, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary The authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. Vulnerability Details
If the email is not registered, the system returns an error message (e.g., "User not found" or a different HTTP status code). This discrepancy allows attackers to programmatically "enumerate" or confirm valid user emails, which can then be used for targeted phishing attacks or brute-force attempts. Steps to Reproduce
Suggested Mitigation Implement a uniform, generic response for all password reset requests, regardless of whether the email exists. Recommended message: "If an account is associated with this email address, a password reset link has been sent." Affected versions
0.21.0
0.21.1
0.21.2
0.21.3
0.21.3.1
0.21.3.2
0.21.3.3
0.21.3.4
0.21.3.5
0.21.3.6
0.21.3.7
0.23.0.0
+ 33 more Show less
0.23.0.1
0.23.0.2
0.23.1.0
0.24.0.0
0.24.0.16
0.24.0.18
0.24.0.19
0.24.0.20
0.24.0.27
0.24.0.42
0.24.0.45
0.24.0.60
0.25.0.0
0.25.0.1
0.25.0.2
0.25.0.30
0.25.0.39
0.25.0.43
0.25.1.0
0.25.2.0
0.25.3.0
0.26.0.0
0.26.1.0
0.26.2.0
0.26.3.0
0.26.3.1
0.26.3.2
0.26.3.3
0.26.3.4
0.27.0.0
0.28.0.0
0.28.3.0
0.28.4.0
Fixed in
0.28.5.0
References Updated Feb 11, 2026 · Source: OSV.dev |
0.24.0.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|