Skip to content
Threat Feed

Vendor

CodeIgniter

4 briefs RSS
high advisory

CodeIgniter Path Traversal via UploadedFile::move()

CodeIgniter Framework versions prior to 4.7.4 contain a path traversal vulnerability in the UploadedFile::move() method that allows attackers to write files to arbitrary filesystem locations when unsanitized client filenames are processed.

CodeIgniter Framework web-application-vulnerability path-traversal codeigniter
2t 1c
critical advisory

SQL Injection in CodeIgniter4 Query Builder deleteBatch Method

A SQL injection vulnerability in CodeIgniter4 (CVE-2026-63221) allows unauthenticated attackers to execute arbitrary SQL via improperly handled where() clauses when using the deleteBatch() method.

CodeIgniter4 Framework web-vulnerability sqli codeigniter4
1t 1c
critical advisory

CodeIgniter4 Unsafe File Upload Validation Bypass

CodeIgniter4 versions before 4.7.4 contain an unsafe file upload validation bypass in 'is_image' and 'mime_in' rules, allowing attackers to upload arbitrary files that could result in remote code execution.

CodeIgniter4 web-application file-upload cve-2026-63223
2t 1c
high threat

CI4MS Stored XSS Vulnerability in Pages Module

A stored XSS vulnerability (CVE-2026-45270) exists in the Pages module of CI4MS due to improper sanitization of page content, allowing an attacker with `pages.create` permissions to inject malicious code and escalate privileges if an administrator views the page.

ci4-cms-erp/ci4ms xss stored-xss ci4ms cve-2026-45270
2r 3t 1i