Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
codeigniter codeigniter vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2012-1915
EllisLab CodeIgniter 2.1.2 allows remote malicious users to bypass the xss_clean() Filter and perform XSS attacks.
Codeigniter Codeigniter
1 EDB exploit
NA
CVE-2022-23556
CodeIgniter is a PHP full-stack web framework. This vulnerability may allow malicious users to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure `Config\App::$proxyIPs`. As a wor...
Codeigniter Codeigniter
NA
CVE-2022-39284
CodeIgniter is a PHP full-stack web framework. In versions before 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed to scripts. It should be no...
Codeigniter Codeigniter
7.5
CVSSv2
CVE-2018-12071
A Session Fixation issue exists in CodeIgniter prior to 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
Codeigniter Codeigniter
6.5
CVSSv2
CVE-2020-10793
CodeIgniter up to and including 4.0.0 allows remote malicious users to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furtherm...
Codeigniter Codeigniter
7.5
CVSSv2
CVE-2015-5725
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter prior to 2.2.4 allows remote malicious users to execute arbitrary SQL commands via vectors involving the offset variable.
Codeigniter Codeigniter
4.3
CVSSv2
CVE-2013-4891
The xss_clean function in CodeIgniter prior to 2.1.4 might allow remote malicious users to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
Codeigniter Codeigniter
5
CVSSv2
CVE-2014-8686
CodeIgniter prior to 2.2.0 makes it easier for malicious users to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
Codeigniter Codeigniter
1 EDB exploit
2 Articles
NA
CVE-2022-46170
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one sessi...
Codeigniter Codeigniter
5
CVSSv2
CVE-2011-3719
CodeIgniter 1.7.2 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.
Codeigniter Codeigniter 1.7.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firmware
CVE-2023-52866
CVE-2024-4367
CVE-2024-1721
CVE-2023-34992
XML injection
CVE-2023-52817
SQL
CVE-2023-52855
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »