CVE-2026-34565 is a critical stored DOM-based Cross-Site Scripting (XSS) vulnerability affecting CI4MS versions prior to 0.31.0.0, a CodeIgniter 4-based CMS. This flaw allows low-privileged users to inject malicious scripts via unsanitized input when adding posts to navigation menus, which are then rendered in administrative dashboards and public navigation menus. With a CVSS score of 9.1 (Critical), it has a network attack vector and low attack complexity, posing a high confidentiality risk. There is currently no evidence of active exploitation or public exploit code, but the vulnerability has garnered some community discussion urging immediate upgrades.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.31.0.0CPE matchmatch criteria | cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.