Codeigniter

Codeigniter

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 31.07.2026 04:03:34
  • Zuletzt bearbeitet 08.09.2026 20:51:43

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to b...

  • EPSS 0.14%
  • Veröffentlicht 31.07.2026 03:50:27
  • Zuletzt bearbeitet 08.09.2026 20:51:43

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the a...

  • EPSS 0.44%
  • Veröffentlicht 17.07.2026 20:36:29
  • Zuletzt bearbeitet 23.07.2026 16:04:11

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided filename extension. As a result,...

  • EPSS 1.5%
  • Veröffentlicht 28.07.2025 14:47:20
  • Zuletzt bearbeitet 05.08.2025 15:46:02

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for image processing (`imagick` as the image library) and either allow file uplo...

  • EPSS 0.32%
  • Veröffentlicht 25.07.2025 17:15:32
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the debugbar_time parameter. NOTE: this is disputed by the Supplier because attacke...

  • EPSS 0.5%
  • Veröffentlicht 20.01.2025 16:15:28
  • Zuletzt bearbeitet 01.08.2025 19:17:42

CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential attacker can construct deliberately malformed headers with Header class. This could disrupt application f...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 15.10.2024 19:15:17
  • Zuletzt bearbeitet 01.08.2025 20:36:13

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

  • EPSS 0.77%
  • Veröffentlicht 29.03.2024 16:15:08
  • Zuletzt bearbeitet 07.05.2025 17:28:25

CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7 or later. ...

  • EPSS 0.62%
  • Veröffentlicht 31.10.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:28:08

CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked. Vers...

  • EPSS 1.13%
  • Veröffentlicht 30.05.2023 04:15:10
  • Zuletzt bearbeitet 21.11.2024 08:03:51

CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-mod...