← Vulnerability feed

Vulnerability record · CVE-2022-24712 · published 28 February 2022

CVE-2022-24712: Codeigniter cross-site request forgery vulnerability

Codeigniter · Codeigniter

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attackers to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism. Users should upgrade to version 4.1.9. There are workarounds for this vulnerability, but users will still need to code as these after upgrading to v4.1.9. Otherwise, the CSRF protection may be bypassed. If auto-routing is enabled, check the request method in the controller method before processing. If auto-routing is disabled, either avoid using `$routes->add()` and instead use HTTP verbs in routes; or check the request method in the controller method before processing.

8.8 CVSS 3.1 High EPSS 0.57% · top 55.3% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 6.8
0.57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attackers to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism. Users should upgrade to version 4.1.9. There are workarounds for this vulnerability, but users will still need to code as these after upgrading to v4.1.9. Otherwise, the CSRF protection may be bypassed. If auto-routing is enabled, check the request method in the controller method before processing. If auto-routing is disabled, either avoid using `$routes->add()` and instead use HTTP verbs in routes; or check the request method in the controller method before processing.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24712 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54418Codeigniter os command injection vulnerabilityCodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the…EPSS 1.5%9.8CVE-2023-32692Codeigniter code injection vulnerabilityCodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. Th…EPSS 1.1%9.8CVE-2022-46170Codeigniter improper authentication vulnerabilityCodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin page…EPSS 0.84%9.8CVE-2022-40826Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note:…EPSS 0.96%9.8CVE-2022-40827Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Mul…EPSS 0.92%9.8CVE-2022-40828Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function.…EPSS 0.96%9.8CVE-2022-40829Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: M…EPSS 0.96%9.8CVE-2022-40830Codeigniter sql injection vulnerabilityB.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. No…EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2022-24712), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.