← Vulnerability feed

Vulnerability record · CVE-2022-21647 · published 4 January 2022

CVE-2022-21647: Codeigniter deserialization of untrusted data vulnerability

Codeigniter · Codeigniter

CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute existing PHP code on the server. We are aware of a working exploit, which can lead to SQL injection. Users are advised to upgrade to v4.1.6 or later. Users unable to upgrade as advised to not use the `old()` function and form_helper nor `RedirectResponse::withInput()` and `redirect()->withInput()`.

9.8 CVSS 3.1 Critical EPSS 38% · top 1.5% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute existing PHP code on the server. We are aware of a working exploit, which can lead to SQL injection. Users are advised to upgrade to v4.1.6 or later. Users unable to upgrade as advised to not use the `old()` function and form_helper nor `RedirectResponse::withInput()` and `redirect()->withInput()`.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-21647 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54418Codeigniter os command injection vulnerabilityCodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the…EPSS 1.5%9.8CVE-2023-32692Codeigniter code injection vulnerabilityCodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. Th…EPSS 1.1%9.8CVE-2022-46170Codeigniter improper authentication vulnerabilityCodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin page…EPSS 0.84%9.8CVE-2022-40826Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note:…EPSS 0.96%9.8CVE-2022-40827Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Mul…EPSS 0.92%9.8CVE-2022-40828Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function.…EPSS 0.96%9.8CVE-2022-40829Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: M…EPSS 0.96%9.8CVE-2022-40830Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. No…EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2022-21647), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.