Ci4-cms-erp

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 36
    Known Exploited: 0
    15
    Critical Level Threats
    6
    High Level Threats
    10
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-45270

    CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule

    Last Modified: Jul 21, 2026
    Published: Jul 20, 2026

    CVE-2026-45139

    CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations

    Last Modified: Jul 20, 2026
    Published: Jul 20, 2026

    CVE-2026-45138

    CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule

    Last Modified: Jul 21, 2026
    Published: Jul 19, 2026

    CVE-2026-41891

    CI4MS: Deactivated User Session Bypass (active=0)

    Last Modified: May 07, 2026
    Published: May 07, 2026

    CVE-2026-41890

    CI4MS: Arbitrary Database Table Drop via Theme deleteProcess

    Last Modified: May 07, 2026
    Published: May 07, 2026
    Items Per Page
    Ci4-Cms-Erp Vulnerabilities & Security CVEs | CVE-DB