Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — including administrators. Because pages may be promoted to the site home page, the payload can be served at `/` and reach every visitor of the site. Version 0.31.9.0 patches the issue. Join the discussion | CVE Database V5 | 07/20/2026, 14:12:13 UTC Added: 07/20/2026, 14:42:39 UTC |
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`), but two destructive endpoints — `deleteFileOrFolder` and `renameFile` — never validate the extension of the *source* path. A backend user with file-editor permissions can therefore unlink or rename any file inside the project root that is not explicitly listed in the small `$hiddenItems` blocklist. Critical framework files such as `app/Config/Routes.php`, `app/Config/App.php`, `app/Config/Database.php`, `app/Config/Filters.php`, `public/index.php`, and `public/.htaccess` all live outside that blocklist and can be destroyed, producing a persistent denial of service that requires filesystem-level redeployment to recover. Version 0.31.9.0 patches the issue. Join the discussion | CVE Database V5 | 07/20/2026, 13:58:39 UTC Added: 07/20/2026, 14:42:39 UTC |
0 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently discarded. The Blog controller writes `$lanData['content']` directly into `blog_langs.content`, and the public template echoes it without escaping — yielding stored XSS executable in any visitor's browser, including the superadmin when previewing or editing posts. Version 0.31.9.0 patches the issue. Join the discussion | CVE Database V5 | 07/19/2026, 23:18:51 UTC Added: 07/19/2026, 23:42:23 UTC |
CI4MS, a CodeIgniter 4-based CMS skeleton, had an insufficient session expiration vulnerability in versions from 0.26.0 up to but not including 0.31.8.0. Specifically, the authentication filter had the deactivated or banned user check commented out, potentially allowing sessions to remain valid longer than intended. This issue has been addressed and patched in version 0.31.8. Join the discussion | CVE Database V5 | 05/07/2026, 03:24:43 UTC Added: 05/07/2026, 04:22:44 UTC |
CI4MS versions from 0.31.1.0 up to but not including 0.31.8.0 contain an improper input validation vulnerability in the deleteProcess() action. This action accepts a POST parameter tables[] with arbitrary table names, which are passed directly to the database dropTable() function without verifying that these tables belong to the theme being deleted. An authenticated administrator can exploit this to drop any table in the database. The issue was patched in version 0. Join the discussion | CVE Database V5 | 05/07/2026, 03:23:31 UTC Added: 05/07/2026, 04:22:44 UTC |
0 CVE-2026-41203 is a critical path traversal vulnerability in the ci4ms product of the ci4-cms-erp project. The issue exists in versions prior to 0.31.5.0 where the Theme::upload function extracts user-uploaded ZIP archives without validating the entry names. This allows an authenticated backend user with theme create permission to write files to arbitrary filesystem locations, potentially leading to remote code execution by placing a PHP file under the public web root. The vulnerability has been patched in version 0.31.5.0. Join the discussion | CVE Database V5 | 05/07/2026, 03:19:45 UTC Added: 05/07/2026, 04:22:40 UTC |
0 CVE-2026-41202 is a critical path traversal vulnerability in ci4ms, a CodeIgniter 4-based CMS. Versions prior to 0.31.5.0 allow an authenticated backend user with backup create permission to upload crafted ZIP archives that can write files to arbitrary filesystem locations. This can lead to remote code execution by placing malicious PHP files under the public web root. The vulnerability has been patched in version 0.31.5.0. Join the discussion | CVE Database V5 | 05/07/2026, 03:18:00 UTC Added: 05/07/2026, 04:22:40 UTC |
0 CVE-2026-41201 is a critical stored DOM-based Cross-site Scripting (XSS) vulnerability in ci4ms version 0.31.4.0, a CodeIgniter 4-based CMS. The vulnerability exists in the backup module's filename field, where an attacker can inject a hidden XSS payload via a manipulated SQL file. Exploitation can lead to full account takeover and privilege escalation. This issue has been patched in version 0.31.5.0. Join the discussion | CVE Database V5 | 05/07/2026, 03:16:41 UTC Added: 05/07/2026, 04:22:40 UTC |
0 CI4MS versions from 0.26.0.0 up to but not including 0.31.7.0 contain a vulnerability in the theme upload feature that allows authenticated backend users with theme-upload permission to upload crafted ZIP files containing PHP code. These PHP files are placed into a web-accessible directory without extension or content filtering, enabling remote code execution via HTTP requests. This vulnerability is identified as CWE-434 (Unrestricted Upload of File with Dangerous Type). A patch fixing this issue is available in version 0. Join the discussion | CVE Database V5 | 05/07/2026, 03:14:38 UTC Added: 05/07/2026, 04:22:40 UTC |
0 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index() controller reads the host POST parameter without any validation and passes it directly into updateEnvSettings(), which writes it into the .env file via preg_replace(). Because newline characters in the value are not stripped, an attacker can inject arbitrary configuration directives into the .env file. The install routes have CSRF protection explicitly disabled, and the InstallFilter can be bypassed when cache('settings') is empty (cache expiry or fresh deployment). This vulnerability is fixed in 0.31.4.0. Join the discussion | CVE Database V5 | 04/08/2026, 14:32:31 UTC Added: 04/09/2026, 05:20:04 UTC |
Showing 1 to 10 of 36 results