CVE-2026-45270: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ci4-cms-erp ci4ms
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — including administrators. Because pages may be promoted to the site home page, the payload can be served at `/` and reach every visitor of the site. Version 0.31.9.0 patches the issue.
AI Analysis
Technical Summary
The vulnerability in ci4ms (CVE-2026-45270) is a stored cross-site scripting (CWE-79) flaw in the Pages backend module of the CMS. Although the module registers an html_purify validation rule, it stores the raw POST data without purification. The public page renderer outputs this unescaped content, enabling stored XSS that executes in the browsers of all visitors, including admins. This can be especially impactful if the compromised page is promoted to the site home page, exposing the payload at the root URL. The issue affects versions prior to 0.31.9.0, which includes all releases before that version. The vulnerability has a CVSS 3.1 score of 8.7, indicating high severity. No official remediation level or patch link is provided in the data, but version 0.31.9.0 is stated as the fixed version.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the affected site for all visitors, including administrators. This can lead to session hijacking, privilege escalation, or other malicious actions within the user's browser. Because the vulnerable page can be set as the home page, the attack surface includes every visitor to the site, increasing the potential impact. There is no indication of denial of service or direct system compromise from this vulnerability.
Mitigation Recommendations
Upgrade ci4ms to version 0.31.9.0 or later, which patches the stored XSS vulnerability by properly handling and escaping page content before rendering. Since no official patch link or temporary fix is provided, applying this version upgrade is the recommended remediation. Until upgraded, avoid promoting untrusted pages to the home page and consider manual content sanitization as a temporary measure.
CVE-2026-45270: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ci4-cms-erp ci4ms
Description
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — including administrators. Because pages may be promoted to the site home page, the payload can be served at `/` and reach every visitor of the site. Version 0.31.9.0 patches the issue.
CVSS v3.1
Score 8.7high
Affected software
pkg:github/ci4-cms-erp/ci4msRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in ci4ms (CVE-2026-45270) is a stored cross-site scripting (CWE-79) flaw in the Pages backend module of the CMS. Although the module registers an html_purify validation rule, it stores the raw POST data without purification. The public page renderer outputs this unescaped content, enabling stored XSS that executes in the browsers of all visitors, including admins. This can be especially impactful if the compromised page is promoted to the site home page, exposing the payload at the root URL. The issue affects versions prior to 0.31.9.0, which includes all releases before that version. The vulnerability has a CVSS 3.1 score of 8.7, indicating high severity. No official remediation level or patch link is provided in the data, but version 0.31.9.0 is stated as the fixed version.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the affected site for all visitors, including administrators. This can lead to session hijacking, privilege escalation, or other malicious actions within the user's browser. Because the vulnerable page can be set as the home page, the attack surface includes every visitor to the site, increasing the potential impact. There is no indication of denial of service or direct system compromise from this vulnerability.
Mitigation Recommendations
Upgrade ci4ms to version 0.31.9.0 or later, which patches the stored XSS vulnerability by properly handling and escaping page content before rendering. Since no official patch link or temporary fix is provided, applying this version upgrade is the recommended remediation. Until upgraded, avoid promoting untrusted pages to the home page and consider manual content sanitization as a temporary measure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-11T18:41:13.156Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5e33df2a4a8d598937d202
Added to database: 07/20/2026, 14:42:39 UTC
Last enriched: 07/20/2026, 14:56:58 UTC
Last updated: 07/21/2026, 05:55:35 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.