Codeigniter
Codeigniter: vulnerabilidades y CVE
Codeigniter tiene 53 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 29 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE53
Últimos 12 meses12
Críticas29
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63223 | Crítica (9.8) | 0.80% | — | 31 jul 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload… |
| CVE-2026-63222 | Alta (7.5) | 0.64% | — | 31 jul 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path… |
| CVE-2026-63221 | Crítica (9.4) | 0.61% | — | 31 jul 2026 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing… |
| CVE-2026-63220 | Media (4.8) | 0.17% | — | 31 jul 2026 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could… |
| CVE-2025-50455 | Crítica (9.1) | 1.2% | — | 27 jul 2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by… |
| CVE-2026-45270 | Alta (8.7) | 0.37% | — | 20 jul 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw,… |
| CVE-2026-45139 | Media (6.5) | 0.48% | — | 20 jul 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write… |
| CVE-2026-48062 | Crítica (9.8) | 0.78% | — | 17 jul 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided… |
| CVE-2026-41890 | Media (6.9) | 0.43% | — | 7 may 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.31.1.0 to before version 0.31.8.0, the deleteProcess() action… |
| CVE-2026-41587 | Alta (8.6) | 0.68% | — | 7 may 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature… |
| CVE-2026-41203 | Crítica (9.4) | 0.72% | — | 7 may 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Theme::upload extracts user uploaded ZIP… |
| CVE-2026-41201 | Crítica (9.1) | 0.56% | — | 7 may 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover &… |
| CVE-2025-54418 | Crítica (9.8) | 1.5% | — | 28 jul 2025 | CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for image processing (`imagick` as the image… |
| CVE-2025-24013 | Media (5.3) | 0.50% | — | 20 ene 2025 | CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential attacker can construct deliberately malformed headers with Header class.… |
| CVE-2024-41344 | Alta (7.5) | 0.23% | — | 15 oct 2024 | A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges. |
| CVE-2024-45622 | Crítica (9.8) | 37% | — | 2 sept 2024 | ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass. |
| CVE-2024-29904 | Alta (7.5) | 0.77% | — | 29 mar 2024 | CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the… |
| CVE-2023-46240 | Alta (7.5) | 0.62% | — | 31 oct 2023 | CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential… |
| CVE-2023-32692 | Crítica (9.8) | 1.1% | — | 30 may 2023 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation… |
| CVE-2022-46170 | Crítica (9.8) | 0.84% | — | 22 dic 2022 | CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`,… |
| CVE-2022-23556 | Alta (7.5) | 0.37% | — | 22 dic 2022 | CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or… |
| CVE-2022-40835 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability |
| CVE-2022-40834 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid… |
| CVE-2022-40833 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid… |
| CVE-2022-40832 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
| CVE-2022-40831 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
| CVE-2022-40830 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid… |
| CVE-2022-40829 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
| CVE-2022-40828 | Crítica (9.8) | 0.96% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid… |
| CVE-2022-40827 | Crítica (9.8) | 0.92% | — | 7 oct 2022 | B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |