Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.23%—Codeigniter15/10/202417/6/2026
A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.
AplazadaCrítica (9.8)36%—Asis Aplikasi Sistem SekolahAICodeigniterAI2/9/202417/6/2026
ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.
ModificadaMedia (5.3)0.52%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap5/7/202417/6/2026
A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the…
ModificadaCrítica (9.8)1.7%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202424/8/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.
AnalizadaAlta (8)1.1%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
AnalizadaAlta (7.5)0.77%—Codeigniter29/3/202417/6/2026
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7 or later.
ModificadaMedia (6.5)0.63%—Codeigniter Shield24/11/202317/6/2026
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be used to send a…
ModificadaMedia (6.5)0.28%—Codeigniter Shield24/11/202317/6/2026
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a malicious person somehow had access to the data in the database, they could use the…
ModificadaAlta (7.5)0.62%—Codeigniter31/10/202317/6/2026
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked. Version 4.4.3 contains a patch. As a workaround, replace…
ModificadaCrítica (9.8)1.1%—Codeigniter30/5/202317/6/2026
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation…
ModificadaMedia (5.9)0.52%—Codeigniter Shield13/3/202317/6/2026
CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the password storage process. All hashed passwords stored in Shield v1.0.0-beta.3 or earlier are easier to crack than expected due to the vulnerability. Therefore, they should be…
ModificadaMedia (6.1)0.61%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap20/1/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.
ModificadaCrítica (9.8)0.88%—Codeigniter22/12/202217/6/2026
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one session cookie (e.g., one for user pages),…
ModificadaAlta (7.5)0.38%—Codeigniter22/12/202217/6/2026
CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure `Config\App::$proxyIPs`. As a workaround, do not use…
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
ModificadaCrítica (9.8)1.1%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
ModificadaCrítica (9.8)1.0%—Codeigniter7/10/202217/6/2026
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.