Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-54418 CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the… Codeigniter 4.6.2+ Fix from $2,3002025-07-28 MEDIUM 5.3 CVE-2025-24013 CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential atta… Codeigniter 4.5.8+ Fix from $1,6002025-01-20 HIGH 7.5 CVE-2024-41344 A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges. Codeigniter No fix yet Fix from $1,9502024-10-15 HIGH 7.5 CVE-2024-29904 CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exp… Codeigniter 4.4.7+ Fix from $1,9502024-03-29 MEDIUM 6.5 CVE-2023-48707 CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authe… Shield Patch available Fix from $1,6002023-11-24 MEDIUM 6.5 CVE-2023-48708 CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded wit… Shield Patch available Fix from $1,6002023-11-24 HIGH 7.5 CVE-2023-46240 CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displ… Codeigniter 4.4.3+ Fix from $1,9502023-10-31 CRITICAL 9.8 CVE-2023-32692 CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. Th… Codeigniter 4.3.5+ Fix from $2,3002023-05-30 MEDIUM 5.9 CVE-2023-27580 CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the passwor… Shield Patch available Fix from $1,6002023-03-13 CRITICAL 9.8 CVE-2022-46170 CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin page… Codeigniter 4.2.11+ Fix from $2,3002022-12-22 HIGH 7.5 CVE-2022-23556 CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse p… Codeigniter 4.2.11+ Fix from $1,9502022-12-22 CRITICAL 9.8 CVE-2022-40826 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note:… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40827 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Mul… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40828 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function.… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40829 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: M… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40830 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. No… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40831 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Mult… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40832 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Mu… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40833 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Not… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40834 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Not… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40835 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parti… Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40824 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: … Codeigniter after 3.1.13 Fix from $2,3002022-10-07 CRITICAL 9.8 CVE-2022-40825 B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: … Codeigniter after 3.1.13 Fix from $2,3002022-10-07 HIGH 8.8 CVE-2022-35943 Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubd… Codeigniter 4.2.3+ Fix from $1,9502022-08-12 HIGH 8.8 CVE-2022-24712 CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attacker… Codeigniter 4.1.9+ Fix from $1,9502022-02-28 CRITICAL 9.8 CVE-2022-24711 CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability all… Codeigniter 4.1.9+ Fix from $2,3002022-02-28 MEDIUM 6.1 CVE-2022-21715 CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseT… Codeigniter 4.1.8+ Fix from $1,6002022-01-24 CRITICAL 9.8 CVE-2022-21647EPSS 38% CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remo… Codeigniter 4.1.6+ Fix from $2,3002022-01-04 HIGH 8.8 CVE-2020-10793 CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contribut… Codeigniter after 4.0.0 Fix from $1,9502020-03-23 MEDIUM 6.1 CVE-2012-1915 EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks. Codeigniter 2.1.2+ Fix from $1,6002020-01-09