CVE-2026-34564 - Vulnerability Analysis
CriticalCVSS: 9.1Last Updated: April 3, 2026
CI4MS - Stored XSS
Overview
CI4MS < 0.31.0.0 contains a stored XSS caused by improper sanitization and output encoding of user-controlled input in Menu Management, letting attackers execute scripts in admin and public navigation menus, exploit requires crafted input.
Severity & Score
Impact
Attackers can execute arbitrary scripts in admin and public interfaces, potentially stealing credentials or performing actions on behalf of users.
Mitigation
Update to version 0.31.0.0 or later.
References
Social Media Activity(1 post)
🚨 CVE-2026-34564 (CRITICAL, CVSS 9.1): ci4ms < 0.31.0.0 vulnerable to stored XSS via Menu Management. Low-priv attackers can inject scripts, impacting admins & users. Patch & audit menus now. https://radar.offseq.com/threat/cve-2026-34564-cwe-79-improper-neutralization-of-i-8f6e6ad8 #OffSeq #XSS #infosec #vuln
View original postRelated Resources
Details
- CVE ID
- CVE-2026-34564
- Severity
- Critical
- CVSS Score
- 9.1
- Type
- stored_xss
- Status
- unconfirmed
- EPSS
- 4.6%
- Social Posts
- 1
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L