CI4-CMS-ERP
22 CVEs tracked since 2026. Since Apr 2026, none of them reached CISA KEV.
CI4-CMS-ERP CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-04 | 22 | 0 |
Products
The products that kept showing up in CI4-CMS-ERP's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting CI4-CMS-ERP.
- CVE-2026-45270CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule8.7
- CVE-2026-45139CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations6.5
- CVE-2026-45138CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule5.4
- CVE-2026-41891CI4MS: Deactivated User Session Bypass (active=0)—
- CVE-2026-41890CI4MS: Arbitrary Database Table Drop via Theme deleteProcess—
- CVE-2026-41203ci4ms Theme::upload is vulnerable to Zip Slip leading to RCE—
- CVE-2026-41202ci4ms Backup::restore is vulnerable to Zip Slip leading to RCE—
- CVE-2026-41201CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS Version 29.1
- CVE-2026-41587CI4MS: Unrestricted PHP File Upload via Theme Installation Leads to Authenticated Remote Code Execution—
- CVE-2026-39394CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller8.1
- CVE-2026-39393Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms8.1
- CVE-2026-39392CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization5.5
- CVE-2026-39391CI4MS has Stored XSS via Unescaped Blacklist Note in Admin User List4.8
- CVE-2026-39390CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting5.5
- CVE-2026-39389CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files6.7
The record
- Peak rank
- #40 in Apr 2026
- Busiest month shown
- Apr 2026, 22 CVEs
- Months with a KEV entry
- 0 since Apr 2026
- Monthly snapshots
- 1 since 2026