Skip to content
Noroxi

codeigniter records

43 published records for vendor codeigniter.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 4.7%
Pre-auth RCE
5
With a fix record
46.5%
Median publish → KEV
No record has entered KEV

All records

43 records
  • CVE-2014-8684
    61This week

    CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and

    CriticalCVSS 9.8WeaponizedEPSS 72%

    codeigniter · codeigniterSep 19, 2017

  • Deserialization of Untrusted Data in Codeigniter4

    CriticalCVSS 9.8No exploitEPSS 38%

    codeigniter · codeigniterJan 4, 2022

  • CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption sch

    CriticalCVSS 9.8WeaponizedEPSS 37%

    codeigniter · codeigniterSep 19, 2017

  • system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the emai

    CriticalCVSS 9.8No exploitEPSS 3%

    codeigniter · codeigniterJan 12, 2017

  • SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute a

    CriticalCVSS 9.8No exploitEPSS 2%

    codeigniter · codeigniterFeb 21, 2018

  • CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    codeigniter · codeigniterJul 28, 2025

  • A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.

    CriticalCVSS 9.8No exploitEPSS 2%

    codeigniter · codeigniterJun 17, 2018

  • Remote CLI Command Execution Vulnerability in CodeIgniter4

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterFeb 28, 2022

  • Remote Code Execution Vulnerability in Validation Placeholders

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    codeigniter · codeigniterMay 30, 2023

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • B.C.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterOct 7, 2022

  • CodeIgniter is vulnerable to improper authentication via Session Handlers

    CriticalCVSS 9.8No exploitEPSS 1%

    codeigniter · codeigniterDec 22, 2022

  • CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page.

    HighCVSS 8.8No exploitEPSS 2%

    codeigniter · codeigniterMar 23, 2020

  • SameSite may allow cross-site request forgery (CSRF) protection to be bypassed

    HighCVSS 8.8No exploitEPSS 1%

    codeigniter · codeigniterAug 12, 2022

  • Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4

    HighCVSS 8.8No exploitEPSS 1%

    codeigniter · codeigniterFeb 28, 2022