Junglewise Threat Intelligence

CVE-2026-34571: CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromi

CVE-2026-34571 · Severity: low · CVSS 3.1 · Published 2026-04-01

Technologies: ci4-cms-erp/ci4ms (Packagist). Vendors: Packagist.

Executive brief

CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise

Affected products

  • Packagist ci4-cms-erp/ci4ms

Related threats