Two high-severity vulnerabilities in CI4MS, a CodeIgniter 4-based CMS skeleton, allow authenticated low-privilege users to trigger stored DOM-based XSS that can lead to full account takeover across roles and privilege escalation. CVE-2026-34558 affects the Methods Management functionality, where improperly sanitized and encoded user input can be stored server-side and later executed in administrative interfaces and global navigation components.
A second flaw, CVE-2026-34565, impacts Menu Management for posts, where malicious post data added to navigation menus can execute in both admin dashboards and public-facing menus. Both issues are classified as CWE-79 and carry the same CVSS v3.1 vector, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L; they affect CI4MS versions prior to 0.31.0.0 and were patched in 0.31.0.0.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
A new CVE, CVE-2026-34989, was published for a stored DOM-based XSS vulnerability in CI4MS Profile & User Management affecting versions prior to 0.31.0.0. The flaw allows a low-privileged authenticated user to inject malicious JavaScript through profile name fields, potentially leading to privilege escalation and full account takeover, and is referenced by GitHub advisory GHSA-vr2g-rhm5-q4jr.
GitHub Security Advisories received a report for CVE-2026-34568 affecting CI4MS Blogs Posts on April 1, 2026. The stored DOM-based XSS flaw impacts versions prior to 0.31.0.0 and could enable privilege escalation and full account takeover through malicious blog post content rendered without proper output encoding.
GitHub's security advisory process received a report for CVE-2026-34563 affecting CI4MS Backup Management. The stored blind DOM-based XSS flaw impacts versions prior to 0.31.0.0 and can enable privilege escalation and full account takeover through malicious backup filename metadata rendered in backup management views.
GitHub Security Advisories received a report for CVE-2026-34564 affecting CI4MS Menu Management for Pages on April 1, 2026. The stored DOM-based XSS flaw impacts versions prior to 0.31.0.0 and can enable privilege escalation and full account takeover through unsanitized page data rendered in admin and public navigation menus.
GitHub Security Advisories received a report for CVE-2026-34566 affecting CI4MS Pages Management on April 1, 2026. The stored DOM-based XSS flaw impacts page creation and editing prior to version 0.31.0.0 and can lead to privilege escalation and account takeover.
GitHub's security advisory process received a report for CVE-2026-34559 affecting CI4MS Blogs Tags. The stored DOM XSS flaw impacts tag creation and editing prior to version 0.31.0.0 and could enable privilege escalation or account takeover from low-privileged access.
CVE-2026-34565 was disclosed for CI4MS, detailing a stored DOM-based XSS vulnerability in the Menu Management (Posts) feature that could affect both administrative dashboards and public-facing navigation menus.
GitHub's security advisory process received the CI4MS Menu Management vulnerability report for CVE-2026-34565. The flaw involved stored DOM-based XSS via post data added to navigation menus.
A vulnerability tracked as CVE-2026-34558 was published for CI4MS, describing a stored DOM-based XSS issue in the Methods Management functionality caused by improper sanitization and output encoding of user-controlled input.
CI4MS released version 0.31.0.0 to patch multiple stored DOM-based XSS vulnerabilities affecting versions prior to 0.31.0.0, including flaws in Methods Management and Menu Management (Posts) that could enable privilege escalation and account takeover.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.