codeigniter4/framework
Packagist12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting codeigniter4/frameworkpage 1 of 1
- CVE-2017-1000247HIGHCVSS 7.5EG 7.5✓ Fixed in 3.1.42017-11-17
vulnerable: 3.1.3
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
- CVE-2020-10793HIGHCVSS 8.8EG 8.82020-03-23
vulnerable: 4.0.0 ... v4.0.0-rc.3 (13 versions)
CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgni…
- CVE-2022-21647HIGHCVSS 7.7EG 7.7✓ Fixed in 4.1.62022-01-04
vulnerable: 4.0.0 ... v4.1.5 (24 versions)
CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possi…
- CVE-2022-21715MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.1.82022-01-24
vulnerable: 4.0.0 ... v4.1.7 (26 versions)
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential …
- CVE-2022-23556HIGHCVSS 7.0EG 7.0✓ Fixed in 4.2.112022-12-22
vulnerable: 4.0.0 ... v4.2.9 (39 versions)
CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configur…
- CVE-2022-24711CRITICALCVSS 9.4EG 9.4✓ Fixed in 4.1.92022-02-28
vulnerable: 4.0.0 ... v4.1.8 (27 versions)
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. Ther…
- CVE-2022-24712MEDIUMCVSS 6.3EG 6.3✓ Fixed in 4.1.92022-02-28
vulnerable: 4.0.0 ... v4.1.8 (27 versions)
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attackers to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism. Users…
- CVE-2022-39284LOWCVSS 2.6EG 2.6✓ Fixed in 4.2.72022-10-06
vulnerable: 4.0.0 ... v4.2.6 (35 versions)
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erro…
- CVE-2022-46170HIGHCVSS 8.6EG 8.6✓ Fixed in 4.2.112022-12-22
vulnerable: 4.0.0 ... v4.2.9 (39 versions)
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHa…
- CVE-2023-32692CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.3.52023-05-30
vulnerable: 4.0.0 ... v4.3.4 (46 versions)
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller…
- CVE-2023-46240HIGHCVSS 7.5EG 7.5✓ Fixed in 4.4.32023-10-31
vulnerable: 4.0.0 ... v4.4.2 (53 versions)
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be l…
- CVE-2024-29904HIGHCVSS 7.5EG 7.5✓ Fixed in 4.4.72024-03-29
vulnerable: 4.0.0 ... v4.4.6 (57 versions)
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7…
Check whether codeigniter4/framework is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for codeigniter4/framework CVEs against the assets you own.
Start Free Scan →