Loading...
Skip to main content
Packagist (PHP)

ci4-cms-erp/ci4ms Security Analysis

ci4-cms-erp/ci4ms has 22 known security vulnerabilities in Packagist (PHP). Upgrade to version 31.0.0.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

22 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 31.0.0.0

Upgrading to 31.0.0.0 or later resolves all 22 known vulnerabilities in ci4-cms-erp/ci4ms. Run: composer require ci4-cms-erp/ci4ms:^31.0.0.0

Is ci4-cms-erp/ci4ms in your project?

Check if you're affected and upgrade to 31.0.0.0 to stay secure.

22
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

22 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-41203
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+48 more)0.31.5.0
CVE-2026-41202
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+48 more)0.31.5.0
CVE-2026-34571
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34569
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34563
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-25510
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+41 more)0.28.5.0
CVE-2026-35035
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+45 more)0.31.2.0
CVE-2026-34568
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34567
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34566
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34565
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34564
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34561
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34560
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34559
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34557
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34558
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-27599
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34989
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CRITICAL
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+52 more)31.0.0.0
CVE-2026-34572
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
HIGH
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-34570
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
HIGH
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+43 more)0.31.0.0
CVE-2026-45270
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
HIGH
0.21.0, 0.21.1, 0.21.2, 0.21.3 (+53 more)0.31.9.0

About This Data

Vulnerability data for ci4-cms-erp/ci4ms is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related Packagist (PHP) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of ci4-cms-erp/ci4ms.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed