Vulnerabilities in codeigniter4

21 results
Vexday analysis

CodeIgniter4 apresenta 17 vulnerabilidades catalogadas, com 4 em nível crítico, mas nenhuma sob exploração ativa conhecida no momento. A fraqueza dominante é falsificação de requisição entre sites (CWE-352), padrão em frameworks web, com apenas 1 nova vulnerabilidade nos últimos 90 dias indicando risco relativamente estável.

CVE-2022-21647HIGHDeserialization of Untrusted Data in Codeigniter4EPSS 37.7%CVE-2025-54418CRITICALCodeIgniter4's ImageMagick Handler has Command Injection VulnerabilityEPSS 1.5%CVE-2022-24711CRITICALRemote CLI Command Execution Vulnerability in CodeIgniter4EPSS 1.2%CVE-2023-32692CRITICALRemote Code Execution Vulnerability in Validation PlaceholdersEPSS 1.1%CVE-2022-21715MEDIUMCross-site Scripting Vulnerability in CodeIgniter4EPSS 1.0%CVE-2022-39284LOWSecure or HttpOnly flag set in Config\Cookie is not reflected in Cookies issued in Codeigniter4EPSS 0.9%CVE-2022-46170HIGHCodeIgniter is vulnerable to improper authentication via Session HandlersEPSS 0.8%CVE-2024-29904HIGHCodeIgniter4 Language class DoS VulnerabilityEPSS 0.8%CVE-2023-48708MEDIUMInsertion of Sensitive Information into Log in codeigniter4/shieldEPSS 0.6%CVE-2023-46240HIGHCodeIgniter4 vulnerable to information disclosure when detailed error report is displayed in production environmentEPSS 0.6%CVE-2022-24712MEDIUMCross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4EPSS 0.6%CVE-2023-27580HIGHCodeIgniter Shield Password Shucking VulnerabilityEPSS 0.5%CVE-2026-63223CRITICALCodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rulesEPSS 0.5%CVE-2025-24013MEDIUMCodeIgniter validation of header name and valueEPSS 0.5%CVE-2022-35943MEDIUMSameSite may allow cross-site request forgery (CSRF) protection to be bypassedEPSS 0.5%CVE-2026-63222HIGHCodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenamesEPSS 0.4%CVE-2026-48062CRITICALCodeIgniter: Uploaded file extension validation bypass in `ext_in` ruleEPSS 0.4%CVE-2026-63221CRITICALCodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditionsEPSS 0.4%CVE-2022-23556HIGHCodeIgniter is vulnerable to IP address spoofing when using proxyEPSS 0.4%CVE-2023-48707MEDIUMCleartext Storage of Sensitive Information in codeigniter4/shieldEPSS 0.3%