CVE-2026-39393
- EPSS 0.42%
- Veröffentlicht 08.04.2026 14:31:44
- Zuletzt bearbeitet 24.07.2026 21:10:00
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the install route guard in ci4ms relies solely on a volatile cache check (cache('settings...
CVE-2026-39392
- EPSS 0.25%
- Veröffentlicht 08.04.2026 14:30:59
- Zuletzt bearbeitet 24.07.2026 21:10:00
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Pages module does not apply the html_purify validation rule to content fields during ...
CVE-2026-39391
- EPSS 0.23%
- Veröffentlicht 08.04.2026 14:30:18
- Zuletzt bearbeitet 20.07.2026 20:10:00
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the blacklist (ban) note parameter in UserController::ajax_blackList_post() is stored in ...
CVE-2026-39390
- EPSS 0.24%
- Veröffentlicht 08.04.2026 14:29:28
- Zuletzt bearbeitet 24.07.2026 21:10:00
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps iframe setting (cMap field) in compInfosPost() sanitizes input using stri...
CVE-2026-39389
- EPSS 0.47%
- Veröffentlicht 08.04.2026 14:28:29
- Zuletzt bearbeitet 24.07.2026 21:10:00
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is fixed in 0.31.4.0.
- EPSS 0.46%
- Veröffentlicht 06.04.2026 16:49:10
- Zuletzt bearbeitet 22.04.2026 18:52:23
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.2.0, the application fails to properly sanitize user-controlled input within System Settings –...
- EPSS 0.3%
- Veröffentlicht 06.04.2026 16:25:54
- Zuletzt bearbeitet 27.04.2026 23:41:16
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 31.0.0.0, the application fails to properly sanitize user-controlled input when users update their ...
CVE-2026-34572
- EPSS 0.5%
- Veröffentlicht 01.04.2026 21:35:10
- Zuletzt bearbeitet 06.04.2026 16:32:05
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account ...
- EPSS 0.39%
- Veröffentlicht 01.04.2026 21:32:16
- Zuletzt bearbeitet 06.04.2026 16:33:14
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend us...
CVE-2026-34570
- EPSS 0.5%
- Veröffentlicht 01.04.2026 21:30:31
- Zuletzt bearbeitet 06.04.2026 18:16:41
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account ...