Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
175 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.28% | — | Codeigniter Shield | 24/11/2023 | 17/6/2026 | CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a malicious person somehow had access to the data in the database, they could use the… | |
| Modificada | Alta (7.5) | 0.62% | — | Codeigniter | 31/10/2023 | 17/6/2026 | CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked. Version 4.4.3 contains a patch. As a workaround, replace… | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | Codeigniter | 30/5/2023 | 17/6/2026 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Igniterealtime Openfire | 26/5/2023 | 17/6/2026 | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an… | |
| Modificada | Media (5.9) | 0.52% | — | Codeigniter Shield | 13/3/2023 | 17/6/2026 | CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the password storage process. All hashed passwords stored in Shield v1.0.0-beta.3 or earlier are easier to crack than expected due to the vulnerability. Therefore, they should be… | |
| Modificada | Media (6.1) | 0.61% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 20/1/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php. | |
| Modificada | Crítica (9.8) | 0.88% | — | Codeigniter | 22/12/2022 | 17/6/2026 | CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one session cookie (e.g., one for user pages),… | |
| Modificada | Alta (7.5) | 0.38% | — | Codeigniter | 22/12/2022 | 17/6/2026 | CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure `Config\App::$proxyIPs`. As a workaround, do not use… | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.0% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codeigniter | 7/10/2022 | 17/6/2026 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | |
| Modificada | Media (4.3) | 1.1% | — | Codeigniter | 6/10/2022 | 17/6/2026 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed to scripts. It should be noted that this vulnerability does not… | |
| Modificada | Media (5.4) | 0.58% | — | Tastyigniter | 8/9/2022 | 17/6/2026 | TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Media (6.1) | 0.59% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 18/8/2022 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | |
| Modificada | Alta (8.8) | 0.59% | — | CodeigniterCodeigniter Shield | 12/8/2022 | 17/6/2026 | Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html) mechanism with CodeIgniter Shield. For this… | |
| Modificada | Media (5.4) | 0.60% | — | Getigniteup Igniteup | 9/5/2022 | 17/6/2026 | The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues |