Medium severity6.7NVD Advisory· Published Apr 8, 2026· Updated Apr 16, 2026
CVE-2026-39389
CVE-2026-39389
Description
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is fixed in 0.31.4.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ci4-cms-erp/ci4msPackagist | < 0.31.4.0 | 0.31.4.0 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-9rxp-f27p-wv3hnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-9rxp-f27p-wv3hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-39389ghsaADVISORY
- github.com/ci4-cms-erp/ci4ms/releases/tag/0.31.4.0ghsaWEB
News mentions
0No linked articles in our index yet.