codeigniter4/framework Security Advisories for v4.3.1 (10)
-
[CRITICAL] CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
PKSA-kcm9-w3rf-jxsk CVE-2026-63223 GHSA-mmj4-63m4-r6h5
Affected version: <4.7.4
Reported by:
GitHub -
[HIGH] CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
PKSA-ykyc-889h-7jxf CVE-2026-63222 GHSA-hhmc-q9hp-r662
Affected version: <4.7.4
Reported by:
GitHub -
[CRITICAL] CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
PKSA-t8h5-ngj8-z43w CVE-2026-63221 GHSA-c9w5-rwh3-7pm9
Affected version: >=4.3.0,<4.7.4
Reported by:
GitHub -
[MEDIUM] CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
PKSA-kcc6-gffv-vchj CVE-2026-63220 GHSA-7wmf-pw8j-mc78
Affected version: <4.7.4
Reported by:
GitHub -
[CRITICAL] CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule
PKSA-217t-qqjr-nkt3 CVE-2026-48062 GHSA-2gr4-ppc7-7mhx
Affected version: <4.7.2
Reported by:
GitHub -
[CRITICAL] CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability
PKSA-7ybs-j1bv-y5mc CVE-2025-54418 GHSA-9952-gv64-x94c
Affected version: <4.6.2
Reported by:
GitHub -
[MEDIUM] Missing validation of header name and value in codeigniter4/framework
PKSA-qbjf-dc24-wrff CVE-2025-24013 GHSA-x5mq-jjr3-vmx6
Affected version: <4.5.8
Reported by:
GitHub -
[HIGH] CodeIgniter4 DoS Vulnerability
PKSA-j54j-8c7k-rccq CVE-2024-29904 GHSA-39fp-mqmm-gxj6
Affected version: <4.4.7
Reported by:
GitHub -
[HIGH] CodeIgniter4 vulnerable to information disclosure when detailed error report is displayed in production environment
PKSA-mscv-ktn8-2rsz CVE-2023-46240 GHSA-hwxf-qxj7-7rfj
Affected version: <=4.4.2
Reported by:
GitHub -
[CRITICAL] Remote Code Execution Vulnerability in Validation Placeholders in CodeIgniter4
PKSA-3xnc-9vd8-pd26 CVE-2023-32692 GHSA-m6m8-6gq8-c9fj
Affected version: <4.3.5
Reported by:
GitHub