Loading HuntDB...

codeigniter4

2 Products 15 CVEs

CVE Severity Distribution (All Time)

Critical
2
High
6
Medium
6
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2025-24013 MEDIUM None

CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential atta…

CVE-2024-29904 HIGH 1 year, 3 months ago

CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exp…

CVE-2023-48707 MEDIUM 1 year, 7 months ago

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authe…

CVE-2023-48708 MEDIUM 1 year, 7 months ago

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded wit…

CVE-2023-46240 HIGH 1 year, 8 months ago

CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displ…

CVE-2023-32692 CRITICAL 2 years, 1 month ago

CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. Th…

CVE-2023-27580 HIGH 2 years, 3 months ago

CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the passwor…

CVE-2022-46170 HIGH 2 years, 6 months ago

CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin page…

CVE-2022-23556 HIGH 2 years, 6 months ago

CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse p…

CVE-2022-39284 LOW 2 years, 9 months ago

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not …