CVE-2026-41587

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP. This issue has been patched in version 0.31.7.0.
CVSS

No CVSS.

Configurations

No configuration.

History

07 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 04:16

Updated : 2026-06-17 10:46


NVD link : CVE-2026-41587

Mitre link : CVE-2026-41587

CVE.ORG link : CVE-2026-41587


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type