codeigniter4/framework Security Advisories for v4.7.2 (4)
-
[CRITICAL] CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
PKSA-kcm9-w3rf-jxsk CVE-2026-63223 GHSA-mmj4-63m4-r6h5
Affected version: <4.7.4
Reported by:
GitHub -
[HIGH] CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
PKSA-ykyc-889h-7jxf CVE-2026-63222 GHSA-hhmc-q9hp-r662
Affected version: <4.7.4
Reported by:
GitHub -
[CRITICAL] CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
PKSA-t8h5-ngj8-z43w CVE-2026-63221 GHSA-c9w5-rwh3-7pm9
Affected version: >=4.3.0,<4.7.4
Reported by:
GitHub -
[MEDIUM] CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
PKSA-kcc6-gffv-vchj CVE-2026-63220 GHSA-7wmf-pw8j-mc78
Affected version: <4.7.4
Reported by:
GitHub