PatchSiren

ci4-cms-erp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ci4-cms-erp CVE published 2026-07-20

CVE-2026-45138

A stored XSS vulnerability exists in CI4MS, a CodeIgniter 4-based content management system skeleton, prior to version 0.31.9.0. The custom `html_purify` validation rule used to sanitize blog post bodies is ineffective due to a by-reference mutation issue with CodeIgniter 4's validator. This allows an attacker to inject malicious code, which is then echoed in the public template without proper escaping, e [truncated]

MEDIUM ci4-cms-erp CVE published 2026-04-08

CVE-2026-39391

CVE-2026-39391 is a stored cross-site scripting vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton. Prior to version 0.31.4.0, the blacklist note parameter is stored in the database without sanitization and rendered into an HTML data-note attribute without escaping. An admin with blacklist privileges can inject arbitrary JavaScript that executes in the browser of any other admin who views the user [truncated]