Security: ci4-cms-erp/ci4ms
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSSGHSA-xgh5-w62m-8mpr published
Mar 31, 2026 by bertugfahriozerCritical -
Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSSGHSA-458r-h248-29c5 published
Mar 31, 2026 by bertugfahriozerCritical -
Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSSGHSA-r33w-c82v-x5v7 published
Mar 31, 2026 by bertugfahriozerCritical -
Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSSGHSA-x7wh-g25g-53vg published
Mar 31, 2026 by bertugfahriozerCritical -
Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSSGHSA-fhrf-q333-82fm published
Mar 31, 2026 by bertugfahriozerCritical -
Account Deletion Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)GHSA-4vxv-4xq4-p84h published
Mar 31, 2026 by bertugfahriozerHigh -
Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account CompromiseGHSA-fc4p-p49v-r948 published
Mar 31, 2026 by bertugfahriozerCritical -
User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSSGHSA-vr2g-rhm5-q4jr published
Apr 2, 2026 by bertugfahriozerCritical -
User Email Enumeration via Password Reset FlowGHSA-654x-9q7r-g966 published
Feb 2, 2026 by bertugfahriozerModerate -
Remote Code Execution (RCE) via Arbitrary File Creation and Save in File EditorGHSA-gp56-f67f-m4px published
Feb 2, 2026 by bertugfahriozerCritical