Ci4 Cms Erp maintains a narrowly scoped portfolio centered on the Ci4ms content management and enterprise resource planning platform, which despite limited product breadth sits among the more prominent vendors in the vulnerability landscape. The vendor's vulnerability profile spans a range of implementation issues across its integrated platform; the recurring exposure suggests defenders should treat this vendor's advisories as part of standard vulnerability-management monitoring for organizations deploying or integrating its products. Current severity, exploitation, and KEV-listing status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ci4 Cms Erp over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39394CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index( | Apr 8, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-34571CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cr | Apr 1, 2026 | 9.0 | 32 | NO | NO |
CVE-2026-34558CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Mar 30, 2026 | 9.0 | 32 | NO | NO |
CVE-2026-34569CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Apr 1, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-34568CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Apr 1, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-34567CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Apr 1, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-34566CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Apr 1, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-34565CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Apr 1, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-34564CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Apr 1, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-34563CRITICAL CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the applica | Apr 1, 2026 | 9.0 | 31 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ci4 Cms Erp.
Media articles that mention a CVE ID that affects a product developed by Ci4 Cms Erp — matched by CVE ID, not by vendor name.