Security: ci4-cms-erp/ci4ms
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Broken access control: media "read" permission grants full file write and deleteGHSA-px9j-875x-44qg published
Jul 26, 2026 by bertugfahriozerModerate -
Unsafe Reflection in dashboard widget `data_source` discloses all password hashesGHSA-3jfm-927m-q5rg published
Jul 26, 2026 by bertugfahriozerHigh -
Remote Code Execution via template-function parsing in page contentGHSA-mvg9-v63p-hp2h published
Jul 26, 2026 by bertugfahriozerCritical -
Stored XSS to admin account takeover via Pages Cover Image URLGHSA-72mr-6rc7-79rh published
Jul 26, 2026 by bertugfahriozerHigh -
Stored XSS in Blog Content via Broken `html_purify` Validation RuleGHSA-2m69-jmvh-6chr published
May 14, 2026 by bertugfahriozerModerate -
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operationsGHSA-245j-xjvr-xvm5 published
May 14, 2026 by bertugfahriozerModerate -
Stored XSS in Pages Module Content via Broken html_purify Validation RuleGHSA-gqr2-7hcg-rchf published
May 14, 2026 by bertugfahriozerHigh -
Deactivated User Session Bypass (active=0)GHSA-5hfv-c864-qcq9 published
Apr 23, 2026 by bertugfahriozerModerate -
Arbitrary Database Table Drop via Theme deleteProcessGHSA-vgrf-pr28-vf98 published
Apr 23, 2026 by bertugfahriozerModerate -
Unrestricted PHP File Upload via Theme Installation Leads to Authenticated Remote Code ExecutionGHSA-fw49-9xq4-gmx6 published
Apr 23, 2026 by bertugfahriozerHigh