CVE-2026-34558

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). This issue has been patched in version 0.31.0.0.
References
Link Resource
https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-v77r-xg3p-75g7 Exploit Vendor Advisory Mitigation
Configurations

Configuration 1 (hide)

cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:*

History

06 Apr 2026, 16:10

Type Values Removed Values Added
CPE cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:*
References () https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-v77r-xg3p-75g7 - () https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-v77r-xg3p-75g7 - Exploit, Vendor Advisory, Mitigation
First Time Ci4-cms-erp
Ci4-cms-erp ci4ms

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) CI4MS es un esqueleto de CMS basado en CodeIgniter 4 que ofrece una arquitectura modular lista para producción con autorización RBAC y soporte de temas. Antes de la versión 0.31.0.0, la aplicación no logra sanear correctamente la entrada controlada por el usuario dentro de la funcionalidad de Gestión de Métodos al crear o gestionar métodos/páginas de la aplicación. Múltiples campos de entrada aceptan cargas útiles de JavaScript controladas por el atacante que se almacenan en el servidor sin saneamiento ni codificación de salida. Estos valores almacenados se renderizan posteriormente directamente en interfaces administrativas y componentes de navegación global sin la codificación adecuada, lo que resulta en Cross-Site Scripting (XSS) persistente basado en DOM. Este problema ha sido parcheado en la versión 0.31.0.0.

30 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 21:17

Updated : 2026-04-06 16:10


NVD link : CVE-2026-34558

Mitre link : CVE-2026-34558

CVE.ORG link : CVE-2026-34558


JSON object : View

Products Affected

ci4-cms-erp

  • ci4ms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')