Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CodeIgniter4 — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in CodeIgniter4, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with the CodeIgniter4 web application framework produced by British Columbia Institute of Technology. It aggregates known security issues affecting this specific version of the popular PHP framework, focusing on flaws that allow attackers to manipulate application behavior or access sensitive data. The collection covers publicly disclosed vulnerabilities from the initial release up to the most recent patches issued by the vendor, ensuring a comprehensive view of the framework's security posture over time. Visitors to this resource can track the evolution of security advisories published by the CodeIgniter community, gaining insight into how specific weakness classes have impacted the software in different releases. By examining the historical data here, developers and security analysts can better understand the context of past incidents, identify recurring patterns in code flaws, and evaluate the effectiveness of mitigation strategies implemented by the maintainers. This aggregation serves as a centralized reference for auditing the framework, allowing teams to assess their exposure to known risks and prioritize updates based on real-world exploitation data. The content is structured to facilitate the lookup of vulnerability histories, helping stakeholders make informed decisions about upgrading or patching their installations to align with current best practices for secure web development.

Vendor: codeigniter4

CVE IDTitleCVSSSeverityPublished
CVE-2026-63223 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules CWE-434 9.8 Critical2026-07-31
CVE-2026-63222 CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames CWE-22 7.5 High2026-07-31
CVE-2026-63221 CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions CWE-89 9.4 Critical2026-07-31
CVE-2026-63220 CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() CWE-348 4.8 Medium2026-07-31
CVE-2026-48062 CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule CWE-434 9.8 Critical2026-07-17
CVE-2025-54418 CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability CWE-78 9.8 Critical2025-07-28
CVE-2025-24013 CodeIgniter validation of header name and value CWE-436 5.3 Medium2025-01-20
CVE-2024-29904 CodeIgniter4 Language class DoS Vulnerability CWE-835 7.5 High2024-03-29
CVE-2023-46240 CodeIgniter4 vulnerable to information disclosure when detailed error report is displayed in production environment CWE-209 7.5 High2023-10-31
CVE-2023-32692 Remote Code Execution Vulnerability in Validation Placeholders CWE-94 9.8 Critical2023-05-30
CVE-2022-46170 CodeIgniter is vulnerable to improper authentication via Session Handlers CWE-287 8.6 High2022-12-22
CVE-2022-23556 CodeIgniter is vulnerable to IP address spoofing when using proxy CWE-345 7.0 High2022-12-22
CVE-2022-39284 Secure or HttpOnly flag set in Config\Cookie is not reflected in Cookies issued in Codeigniter4 CWE-665 2.6 Low2022-10-06
CVE-2022-24712 Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4 CWE-352 6.3 Medium2022-02-28
CVE-2022-24711 Remote CLI Command Execution Vulnerability in CodeIgniter4 CWE-20 9.4 Critical2022-02-28
CVE-2022-21715 Cross-site Scripting Vulnerability in CodeIgniter4 CWE-79 5.4 Medium2022-01-24
CVE-2022-21647 Deserialization of Untrusted Data in Codeigniter4 CWE-502 7.7 High2022-01-04

All 17 known CVE vulnerabilities affecting CodeIgniter4 with full Chinese analysis, references, and POCs where available.