VendorsCi4-cms-erpci4msany version
Vulnerabilities

Ci4-cms-erp ci4ms any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2026-25510
CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
Published 2026-02-03 · Analyzed
9.9EPSS 0.010
CVE-2026-34571
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
Published 2026-04-01 · Analyzed
9.9EPSS 0.006
CVE-2026-34569
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.9EPSS 0.005
CVE-2026-39394
CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
Published 2026-04-08 · Analyzed
9.8EPSS 0.005
CVE-2026-34989
CI4MS affected by Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-06 · Analyzed
9.4EPSS 0.004
CVE-2026-34560
CI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.005
CVE-2026-34559
CI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34563
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34564
CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34565
CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34566
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34567
CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34568
CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34557
CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-03-30 · Analyzed
9.1EPSS 0.004
CVE-2026-34558
CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-03-30 · Analyzed
9.1EPSS 0.004
CVE-2026-35035
CI4MS Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
Published 2026-04-06 · Analyzed
9.0EPSS 0.006
CVE-2026-34562
CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
9.0EPSS 0.004
CVE-2026-34570
CI4MS: Account Deletion Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
Published 2026-04-01 · Modified
8.8EPSS 0.007
CVE-2026-34572
CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
Published 2026-04-01 · Analyzed
8.8EPSS 0.007
CVE-2026-34561
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-04-01 · Analyzed
8.4EPSS 0.004
CVE-2026-39393
Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms
Published 2026-04-08 · Analyzed
8.1EPSS 0.004
CVE-2026-39389
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
Published 2026-04-08 · Analyzed
7.2EPSS 0.005
CVE-2026-27599
CI4MS: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Published 2026-03-30 · Analyzed
7.2EPSS 0.004
CVE-2026-39392
CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization
Published 2026-04-08 · Analyzed
5.5EPSS 0.003
CVE-2026-39390
CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting
Published 2026-04-08 · Analyzed
5.5EPSS 0.002
CVE-2026-25509
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
Published 2026-02-03 · Analyzed
5.3EPSS 0.004
CVE-2026-39391
CI4MS has Stored XSS via Unescaped Blacklist Note in Admin User List
Published 2026-04-08 · Analyzed
4.8EPSS 0.003