Security: ci4-cms-erp/ci4ms
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Backup Management filename field - Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS Version 2GHSA-qxpq-82f3-xj47 published
Apr 18, 2026 by bertugfahriozerCritical -
ci4ms Backup::restore is vulnerable to Zip Slip leading to RCEGHSA-xp9f-pvvc-57p4 published
Apr 18, 2026 by bertugfahriozerCritical -
ci4ms Theme::upload is vulnerable to Zip Slip leading to RCEGHSA-xv3r-vr59-95rg published
Apr 18, 2026 by bertugfahriozerCritical -
Stored XSS via Unescaped Blacklist Note in Admin User ListGHSA-7cm9-v848-cfh2 published
Apr 7, 2026 by bertugfahriozerModerate -
Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected FilesGHSA-9rxp-f27p-wv3h published
Apr 7, 2026 by bertugfahriozerModerate -
Stored XSS via srcdoc attribute bypass in Google Maps iframe settingGHSA-x3hr-cp7x-44r2 published
Apr 7, 2026 by bertugfahriozerModerate -
Stored XSS in Pages Content Due to Missing html_purify SanitizationGHSA-fjpj-6qcq-6pw2 published
Apr 7, 2026 by bertugfahriozerModerate -
Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4msGHSA-8rh5-4mvx-xj7j published
Apr 7, 2026 by bertugfahriozerHigh -
.env CRLF Injection via Unvalidated `host` Parameter in Install ControllerGHSA-vfhx-5459-qhqh published
Apr 7, 2026 by bertugfahriozerHigh -
Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSSGHSA-5ghq-42rg-769x published
Apr 2, 2026 by bertugfahriozerCritical