18 Total CVEs
18 AI Analyzed
0 CISA KEV
14 Critical

Profile

0% ended up actively exploited 0 of 18 added to CISA KEV
78% rated critical (CVSS 9.0+) 14 critical, 4 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

18 CVEs in the last 12 months

Products

  • CI4MS (CodeIgniter 4 CMS)2
  • CI4MS (CMS skeleton)2
  • ci4ms1
  • CI4MS1
  • CMS Skeleton1

5 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-18 of 18 CVEs
CVE-2026-45270
Analyzed
8.7
ci4-cms-erp ci4ms

CI4MS is a CodeIgniter 4-based content management system skeleton

2026-07-21
CVE-2026-41201
Analyzed
9.1
ci4-cms-erp CI4MS

CI4MS contains a stored DOM-based XSS vulnerability in the backup module that can be leveraged for full account takeover.

2026-05-07
CVE-2026-39394
Analyzed
8.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support

2026-04-09
CVE-2026-39393
Analyzed
8.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support

2026-04-09
CVE-2026-34572
Analyzed
8.8
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support

2026-04-02
CVE-2026-34571
Analyzed
9.9
ci4-cms-erp CI4MS (CodeIgniter 4 CMS)

A Stored Cross-Site Scripting (XSS) vulnerability in the CI4MS backend user management allows attackers to inject malicious JavaScript, leading to ful...

2026-04-02
CVE-2026-34569
Analyzed
9.9
ci4-cms-erp CI4MS (CodeIgniter 4 CMS)

CI4MS versions prior to 0.31.0.0 are vulnerable to Stored XSS in the blog category title field, allowing malicious scripts to execute on both public a...

2026-04-02
CVE-2026-34568
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34567
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34566
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34565
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34564
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34563
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34560
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34559
Analyzed
9.1
ci4-cms-erp Multiple Products

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

2026-04-02
CVE-2026-34558
Analyzed
9.1
ci4-cms-erp CI4MS (CMS skeleton)

CI4MS is vulnerable to Stored DOM-Based Cross-Site Scripting in its Methods Management functionality, allowing for script execution in administrative...

2026-03-31
CVE-2026-34557
Analyzed
9.1
ci4-cms-erp CI4MS (CMS skeleton)

CI4MS is vulnerable to stored Cross-Site Scripting (XSS) in its group and role management functionality, allowing attackers to execute malicious scrip...

2026-03-31
CVE-2026-25510
Analyzed
9.9
ci4-cms-erp CMS Skeleton

An authenticated user with file editor permissions in CI4MS can achieve Remote Code Execution (RCE) by uploading and executing arbitrary PHP code via...

2026-02-04