CVE-2026-63223: CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allow
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads using is_image or mime_in without an independent safe extension check (such as ext_in on patched versions), save uploaded files using the client-supplied filename, and place uploads in a web-accessible directory where PHP files can execute. This issue is fixed in version 4.7.4.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-63223
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-632230.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-63223 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for CodeIgniter is a
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-63222: CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() wi…nvd · 2026-07-31
- criticalCVE-2026-63221: CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteB…nvd · 2026-07-31
- mediumCVE-2026-63220: CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::is…nvd · 2026-07-31
- highCVE-2026-45270: CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, …nvd · 2026-07-20
- mediumCVE-2026-45139: CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, …nvd · 2026-07-20
- mediumCVE-2026-45138: CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, …nvd · 2026-07-20
More from NVD Recent CVEs
- unknownCVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central all…2026-08-01
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01