
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34561 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in the System Settings – Social Media Management module, where user-controlled input in Social Media and Social Media Link fields is stored server-side and rendered without proper output encoding. All versions up to and including 0.28.6.0 are affected; the issue was patched in version 0.31.0.0. The advisory was published on March 31, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) by GitHub Advisory, though NVD records a score of 8.4 (High) (Github Advisory, CI4MS Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored DOM XSS variant where attacker-controlled input breaks out of HTML input attribute context on the same settings page (/backend/settings/) (Github Advisory). Unlike typical stored XSS that executes on public-facing pages, this payload executes immediately upon re-rendering the Social Media Management settings page in the authenticated user's browser, without requiring a separate victim to visit a different page. Exploitation requires high privileges (administrator-level access) to submit configuration values, but no additional user interaction is needed once the payload is stored — the script fires automatically when the settings page is loaded. A proof-of-concept payload demonstrating attribute context breakout is publicly documented: test"><img src=1 onerror=alert()>" class="form-control" placeholder="Name" required> (CI4MS Advisory).
Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of any authenticated user who views the Social Media Management settings page, including other administrators. This can lead to full administrator account takeover, privilege escalation across all roles, session cookie theft, and complete platform compromise. Because the payload persists in the application's configuration store, every subsequent page load by any privileged user triggers the malicious script, amplifying the blast radius beyond the initial attacker's session (Github Advisory, CI4MS Advisory).
A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, including a video PoC hosted externally (CI4MS Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.038% (0.000380), placing it in the 24th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
System Settings → Social Media Management (endpoint: /backend/settings/).test"><img src=1 onerror=alert()>" class="form-control" placeholder="Name" required>alert() with a more harmful payload (e.g., cookie exfiltration via document.cookie, credential harvesting, or CSRF-via-XSS) to achieve session hijacking, account takeover, or lateral privilege escalation across all roles (CI4MS Advisory)./backend/settings/ containing HTML special characters (<, >, ", onerror, alert, script) in Social Media configuration fields; repeated access to the settings page by multiple distinct admin accounts in a short timeframe.onerror, onload), or <script> elements.The vendor has released a patch in CI4MS version 0.31.0.0, which implements global input validation, enhanced XSS protection, and CSRF token improvements as part of a major security and framework update (CI4MS Release). All users running version 0.28.6.0 or earlier should upgrade immediately; it is recommended to back up the database and run composer update before upgrading due to major structural changes including Shield authentication migration. As interim workarounds for environments that cannot immediately upgrade, administrators should implement strict HTML entity encoding on all user-controlled data before rendering, avoid unsafe DOM manipulation methods (innerHTML, .html()), enforce a Content Security Policy (CSP), and set HttpOnly, SameSite, and Secure flags on session cookies (Github Advisory).
The vulnerability was reported by researchers credited as bugmithlegend and LAW6ZX7 in the GitHub Security Advisory (CI4MS Advisory). The advisory was noted by automated CVE tracking feeds including cvefeed.io and radar.offseq.com shortly after publication, and the CVE was picked up by the ENISA European Vulnerability Database (EUVD-2026-18073). No significant broader media coverage or notable security researcher commentary beyond the advisory itself has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."