Medium severity5.4GHSA Advisory· Published Jul 20, 2026· Updated Jul 21, 2026
CVE-2026-45138
CVE-2026-45138
Description
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom html_purify validation rule used to sanitize blog post bodies relies on by-reference mutation (?string &$str), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently discarded. The Blog controller writes $lanData['content'] directly into blog_langs.content, and the public template echoes it without escaping — yielding stored XSS executable in any visitor's browser, including the superadmin when previewing or editing posts. Version 0.31.9.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ci4-cms-erp/ci4msPackagist | < 0.31.9.0 | 0.31.9.0 |
Affected products
1- Range: <= 0.31.8.0
Patches
Vulnerability mechanics
References
3News mentions
1- CI4MS: Three High-Severity Bugs Disclosed — Stored XSS and Fileeditor FlawsVypr Intelligence · May 18, 2026