VDB
Sign up

package

Packagist/ci4-cms-erp/ci4ms

pkg:packagist/ci4-cms-erp/ci4ms

MEDIUM6.5Packagist
GHSA-245j-xjvr-xvm5· CVE-2026-45139

CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations

Modified: 5/18/2026

HIGH8.8Packagist
GHSA-4vxv-4xq4-p84h· CVE-2026-34570

CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)

Modified: 4/6/2026

CRITICAL9.1Packagist
GHSA-5ghq-42rg-769x· CVE-2026-35035

CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS

Modified: 5/5/2026

CRITICAL9.1Packagist
GHSA-66m2-v9v9-95c3· CVE-2026-27599

ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 5/5/2026

CRITICAL9.9Packagist
GHSA-85m8-g393-jcxf· CVE-2026-34563

CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS

Modified: 5/5/2026

HIGH8.8Packagist
GHSA-8fq3-c5w3-pj3q· CVE-2026-34572

CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)

Modified: 5/5/2026

MEDIUM6.7Packagist
GHSA-9rxp-f27p-wv3h· CVE-2026-39389

CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files

Modified: 4/8/2026

CRITICAL9.9Packagist
GHSA-fc4p-p49v-r948· CVE-2026-34571

CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise

Modified: 4/6/2026

CRITICAL9.1Packagist
GHSA-g4pp-fhgf-8653· CVE-2026-34564

CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 4/6/2026

CRITICAL9.1Packagist
GHSA-gcfj-cf7j-vwgj· CVE-2026-34561

CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 5/5/2026

MEDIUM6.8Packagist
GHSA-qxpq-82f3-xj47· CVE-2026-41201

CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS

Modified: 5/8/2026

CRITICAL9.1Packagist
GHSA-r33w-c82v-x5v7· CVE-2026-34567

CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 4/6/2026

CRITICAL9.1Packagist
GHSA-rpjr-985c-qhvm· CVE-2026-34557

CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 4/1/2026

MEDIUM4.7Packagist
GHSA-v897-c6vq-6cr3· CVE-2026-34562

CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 4/6/2026

CRITICAL9.0Packagist
GHSA-vr2g-rhm5-q4jr· CVE-2026-34989

CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 9/10/2026

CRITICAL9.1Packagist
GHSA-xgh5-w62m-8mpr· CVE-2026-34565

CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

Modified: 4/6/2026