CVE-2026-39389

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is fixed in 0.31.4.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:*

History

16 Apr 2026, 00:19

Type Values Removed Values Added
References () https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-9rxp-f27p-wv3h - () https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-9rxp-f27p-wv3h - Exploit, Vendor Advisory
First Time Ci4-cms-erp
Ci4-cms-erp ci4ms
CPE cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:*

08 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 15:16

Updated : 2026-04-16 00:19


NVD link : CVE-2026-39389

Mitre link : CVE-2026-39389

CVE.ORG link : CVE-2026-39389


JSON object : View

Products Affected

ci4-cms-erp

  • ci4ms
CWE
CWE-285

Improper Authorization