Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Codeigniter CRITICAL 9.8
CVE-2018-12071

A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.

Fix: 3.1.9+
Fix from $2,300 2018-06-17
Codeigniter CRITICAL 9.8
CVE-2015-5725

SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary …

Fix: 2.2.4+
Fix from $2,300 2018-02-21
Codeigniter MEDIUM 6.1
CVE-2013-4891

The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scr…

Fix: 2.1.4+
Fix from $1,600 2018-02-21
Codeigniter HIGH 7.5
CVE-2017-1000247

British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Ap…

Mitigation only
Fix from $1,950 2017-11-17
Codeigniter CRITICAL 9.8
CVE-2014-8684EPSS 72%

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and conseque…

Fix: after 2.2.6
Fix from $2,300 2017-09-19
Codeigniter CRITICAL 9.8
CVE-2014-8686EPSS 37%

CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when …

Fix: after 2.1.4
Fix from $2,300 2017-09-19
Codeigniter CRITICAL 9.8
CVE-2016-10131

system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from f…

Fix: after 3.1.2
Fix from $2,300 2017-01-12
Codeigniter MEDIUM 5.0
CVE-2011-3719

CodeIgniter 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

No fix yet
Fix from $1,600 2011-09-23
Codeigniter MEDIUM 5.0
CVE-2007-3707

Directory traversal vulnerability in index.php in CodeIgniter 1.5.3 before 20070628, when enable_query_strings is true, allows remote attackers to re…

Mitigation only
Fix from $1,600 2007-07-11
Codeigniter MEDIUM 5.0
CVE-2007-3709

CRLF injection vulnerability in the redirect function in url_helper.php in CodeIgniter 1.5.3 allows remote attackers to inject arbitrary HTTP headers…

Mitigation only
Fix from $1,600 2007-07-11