CVE-2026-34563 - Vulnerability Analysis
CriticalCVSS: 9.1Last Updated: April 1, 2026
CI4MS - Stored XSS
Published: April 1, 2026Updated: April 1, 2026Remote Exploitable
Overview
CI4MS < 0.31.0.0 contains a stored XSS caused by improper sanitization of backup upload filenames and unsafe rendering in backup management views, letting attackers inject and execute JavaScript payloads, exploit requires uploading a crafted backup file.
Severity & Score
Severity: Critical
CVSS Score: 9.1
Impact
Attackers can execute arbitrary JavaScript in the context of the application, potentially leading to session hijacking or user impersonation.
Mitigation
Update to version 0.31.0.0 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-34563
- Severity
- Critical
- CVSS Score
- 9.1
- Type
- stored_xss
- Status
- new
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L