CVE-2026-34569 is a critical stored Cross-Site Scripting (XSS) vulnerability affecting CI4MS, a CodeIgniter 4-based CMS, in versions prior to 0.31.0.0. This flaw allows an authenticated attacker with low privileges to inject malicious JavaScript into blog category titles due to insufficient input sanitization. Rated 9.9 Critical on the CVSS scale, this vulnerability has a network attack vector and low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability, including full system compromise. The injected payload is persistently stored and rendered unsafely across public blog pages, administrative interfaces, and blog post views. While there is no known active exploitation or public exploit code available, the vulnerability has garnered community attention, with urgent recommendations to update to version 0.31.0.0 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.31.0.0CPE matchmatch criteria | cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.