Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Codeigniter CRITICAL 9.8
CVE-2025-54418

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the…

Fix: 4.6.2+
Fix from $2,300 2025-07-28
Codeigniter MEDIUM 5.3
CVE-2025-24013

CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential atta…

Fix: 4.5.8+
Fix from $1,600 2025-01-20
Codeigniter HIGH 7.5
CVE-2024-41344

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

No fix yet
Fix from $1,950 2024-10-15
Codeigniter HIGH 7.5
CVE-2024-29904

CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exp…

Fix: 4.4.7+
Fix from $1,950 2024-03-29
Shield MEDIUM 6.5
CVE-2023-48707

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authe…

Patch available
Fix from $1,600 2023-11-24
Shield MEDIUM 6.5
CVE-2023-48708

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded wit…

Patch available
Fix from $1,600 2023-11-24
Codeigniter HIGH 7.5
CVE-2023-46240

CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displ…

Fix: 4.4.3+
Fix from $1,950 2023-10-31
Codeigniter CRITICAL 9.8
CVE-2023-32692

CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. Th…

Fix: 4.3.5+
Fix from $2,300 2023-05-30
Shield MEDIUM 5.9
CVE-2023-27580

CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the passwor…

Patch available
Fix from $1,600 2023-03-13
Codeigniter CRITICAL 9.8
CVE-2022-46170

CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin page…

Fix: 4.2.11+
Fix from $2,300 2022-12-22
Codeigniter HIGH 7.5
CVE-2022-23556

CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse p…

Fix: 4.2.11+
Fix from $1,950 2022-12-22
Codeigniter CRITICAL 9.8
CVE-2022-40826

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note:…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40827

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Mul…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40828

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function.…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40829

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: M…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40830

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. No…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40831

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Mult…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40832

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Mu…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40833

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Not…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40834

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Not…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40835

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parti…

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40824

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: …

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter CRITICAL 9.8
CVE-2022-40825

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: …

Fix: after 3.1.13
Fix from $2,300 2022-10-07
Codeigniter HIGH 8.8
CVE-2022-35943

Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubd…

Fix: 4.2.3+
Fix from $1,950 2022-08-12
Codeigniter HIGH 8.8
CVE-2022-24712

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attacker…

Fix: 4.1.9+
Fix from $1,950 2022-02-28
Codeigniter CRITICAL 9.8
CVE-2022-24711

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability all…

Fix: 4.1.9+
Fix from $2,300 2022-02-28
Codeigniter MEDIUM 6.1
CVE-2022-21715

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseT…

Fix: 4.1.8+
Fix from $1,600 2022-01-24
Codeigniter CRITICAL 9.8
CVE-2022-21647EPSS 38%

CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remo…

Fix: 4.1.6+
Fix from $2,300 2022-01-04
Codeigniter HIGH 8.8
CVE-2020-10793

CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contribut…

Fix: after 4.0.0
Fix from $1,950 2020-03-23
Codeigniter MEDIUM 6.1
CVE-2012-1915

EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.

Fix: 2.1.2+
Fix from $1,600 2020-01-09