Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2026-63223

Medium priority
Needs evaluation

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content...

1 affected package

php-codeigniter-framework

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-codeigniter-framework Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-63222

Medium priority
Needs evaluation

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal...

1 affected package

php-codeigniter-framework

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-codeigniter-framework Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-63221

Medium priority
Needs evaluation

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled...

1 affected package

php-codeigniter-framework

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-codeigniter-framework Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-63220

Medium priority
Needs evaluation

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these...

1 affected package

php-codeigniter-framework

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-codeigniter-framework Needs evaluation Needs evaluation Not in release — —
Show less packages