So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:

  • SQL Injection (CVE-2026-63221)
  • Path traversal (CVE-2026-63222)
  • HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

https://securityonline.info/codeigniter4-rce-vulnerability/

#cybersecurity #infosec #codeigniter #vulnerability