Codeigniter
44 known vulnerabilities
Top Products
CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affe
CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name
A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator passw
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks.
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful lo
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an import
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a d
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you us
CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementa
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user
CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `tru
Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attack
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerabilit
CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` f
CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was m
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote at
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechani
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_head
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging c
Frequently Asked Questions
How many CVEs affect Codeigniter?
Codeigniter has 44 CVE records in our database, including 20 critical and 9 high severity vulnerabilities.
What are the most severe Codeigniter vulnerabilities?
Codeigniter has 20 critical severity (CVSS 9.0+) and 9 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Codeigniter vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Codeigniter products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Codeigniter Vulnerabilities
CyberStrike scans your infrastructure for Codeigniter vulnerabilities and provides real-time remediation guidance.
Get Started