Skip to main content

Vendor archive

codeigniter CVEs

Beta · best-effort

43 CVEs tagged to vendor codeigniter20 Critical, 9 High, 12 Medium, 2 Low, 0 Unrated.

CVE-2025-54418

Published Jul 28, 2025

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for image…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-24013

Published Jan 20, 2025

CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential attacker can construct deliberatel…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2024-41344

Published Oct 15, 2024

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29904

Published Mar 29, 2024

CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48708

Published Nov 24, 2023

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48707

Published Nov 24, 2023

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected vers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46240

Published Oct 31, 2023

CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32692

Published May 30, 2023

CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27580

Published Mar 13, 2023

CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the password storage process. All hashed…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46170

Published Dec 22, 2022

CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23556

Published Dec 22, 2022

CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patc…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40835

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40834

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40833

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40832

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40831

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disput…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40830

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties hav…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40829

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have dis…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40828

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40827

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have dispu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40826

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have d…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40825

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have di…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40824

Published Oct 7, 2022

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have di…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-39284

Published Oct 6, 2022

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 43 CVEsPage 1 of 2