Junglewise Threat Intelligence

CVE-2026-35035: CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via Syst

CVE-2026-35035 · Severity: low · CVSS 3.1 · Published 2026-04-06

Technologies: ci4-cms-erp/ci4ms (Packagist). Vendors: Packagist.

Executive brief

CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS

Affected products

  • Packagist ci4-cms-erp/ci4ms

Related threats