PatchSiren

ci4-cms-erp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ci4-cms-erp CVE published 2026-07-20

CVE-2026-45270

CVE-2026-45270 is a stored XSS vulnerability in the CI4MS Pages backend module. The vulnerability allows an attacker to inject malicious code into page content, which is then executed by the public renderer. This issue was patched in version 0.31.9.0. The vulnerability has a high impact on the system, and administrators should take immediate action to protect their systems. The vulnerability is caused by [truncated]

MEDIUM ci4-cms-erp CVE published 2026-07-20

CVE-2026-45139

A medium-severity vulnerability was found in CI4MS, a CodeIgniter 4-based content management system skeleton. The Fileeditor module does not validate the extension of the source path for destructive operations, allowing backend users with file-editor permissions to unlink or rename critical framework files, leading to a persistent denial of service. This vulnerability requires filesystem-level redeploymen [truncated]

MEDIUM ci4-cms-erp CVE published 2026-07-20

CVE-2026-45138

A stored XSS vulnerability exists in CI4MS, a CodeIgniter 4-based content management system skeleton, prior to version 0.31.9.0. The custom `html_purify` validation rule used to sanitize blog post bodies is ineffective due to a by-reference mutation issue with CodeIgniter 4's validator. This allows an attacker to inject malicious code, which is then echoed in the public template without proper escaping, e [truncated]

MEDIUM ci4-cms-erp CVE published 2026-04-08

CVE-2026-39391

CVE-2026-39391 is a stored cross-site scripting vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton. Prior to version 0.31.4.0, the blacklist note parameter is stored in the database without sanitization and rendered into an HTML data-note attribute without escaping. An admin with blacklist privileges can inject arbitrary JavaScript that executes in the browser of any other admin who views the user [truncated]