ci4-cms-erp/ci4ms Security Analysis
ci4-cms-erp/ci4ms has 22 known security vulnerabilities in Packagist (PHP). Upgrade to version 31.0.0.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 31.0.0.0
Upgrading to 31.0.0.0 or later resolves all 22 known vulnerabilities in ci4-cms-erp/ci4ms. Run: composer require ci4-cms-erp/ci4ms:^31.0.0.0
Is ci4-cms-erp/ci4ms in your project?
Check if you're affected and upgrade to 31.0.0.0 to stay secure.
Vulnerabilities
22 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-41203 CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+48 more) | 0.31.5.0 |
| CVE-2026-41202 CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+48 more) | 0.31.5.0 |
| CVE-2026-34571 CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34569 CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34563 CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-25510 CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+41 more) | 0.28.5.0 |
| CVE-2026-35035 CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+45 more) | 0.31.2.0 |
| CVE-2026-34568 CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34567 CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34566 CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34565 CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34564 CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34561 CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34560 CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34559 CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34557 CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34558 CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-27599 ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34989 CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CRITICAL | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+52 more) | 31.0.0.0 |
| CVE-2026-34572 CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw) | HIGH | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-34570 CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw) | HIGH | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more) | 0.31.0.0 |
| CVE-2026-45270 CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule | HIGH | 0.21.0, 0.21.1, 0.21.2, 0.21.3 (+53 more) | 0.31.9.0 |
About This Data
Vulnerability data for ci4-cms-erp/ci4ms is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Packagist (PHP) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of ci4-cms-erp/ci4ms.