UNKNOWNCVE-2026-34564

CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Platform

codeigniter

Component

ci4ms

Fixed in

0.31.0.0

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management functionality. Page-related data selected via the Pages section is stored server-side and rendered without proper output encoding. This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). This issue has been patched in version 0.31.0.0.

How to fix

Actualice ci4ms a la versión 0.31.0.0 o superior. Esta versión corrige la vulnerabilidad de XSS almacenado en la gestión de menús, evitando la ejecución de código malicioso en el navegador de los usuarios.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free
CVE-2026-34564 — Vulnerability Details | NextGuard | NextGuard