Description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. This issue has been patched in version 0.31.0.0.

INFO

Published Date :

2026-04-01T21:32:16.629Z

Last Modified :

2026-04-02T16:23:34.783Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-34571 vulnerability.

Vendors Products
Ci4-cms-erp
  • Ci4ms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-34571.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact