CVE Tools

CI4-CMS-ERP

22 CVEs tracked since 2026. Since Apr 2026, none of them reached CISA KEV.

CI4-CMS-ERP CVEs per month

Apr 2026 to Apr 2026. Point at a month, or focus the strip and use the arrow keys.
CI4-CMS-ERP CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-04220

Products

The products that kept showing up in CI4-CMS-ERP's monthly top three, with their CVEs summed over those months.

  1. CI4MS221 month

Latest CVEs

The 15 most recently published vulnerabilities affecting CI4-CMS-ERP.

  1. CVE-2026-45270CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule8.7
  2. CVE-2026-45139CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations6.5
  3. CVE-2026-45138CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule5.4
  4. CVE-2026-41891CI4MS: Deactivated User Session Bypass (active=0)—
  5. CVE-2026-41890CI4MS: Arbitrary Database Table Drop via Theme deleteProcess—
  6. CVE-2026-41203ci4ms Theme::upload is vulnerable to Zip Slip leading to RCE—
  7. CVE-2026-41202ci4ms Backup::restore is vulnerable to Zip Slip leading to RCE—
  8. CVE-2026-41201CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS Version 29.1
  9. CVE-2026-41587CI4MS: Unrestricted PHP File Upload via Theme Installation Leads to Authenticated Remote Code Execution—
  10. CVE-2026-39394CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller8.1
  11. CVE-2026-39393Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms8.1
  12. CVE-2026-39392CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization5.5
  13. CVE-2026-39391CI4MS has Stored XSS via Unescaped Blacklist Note in Admin User List4.8
  14. CVE-2026-39390CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting5.5
  15. CVE-2026-39389CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files6.7

The record

Peak rank
#40 in Apr 2026
Busiest month shown
Apr 2026, 22 CVEs
Months with a KEV entry
0 since Apr 2026
Monthly snapshots
1 since 2026
CI4-CMS-ERP's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store