THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-63223 (CRITICAL 9.8) — CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename

[NVD] CVE-2026-63223 (CRITICAL 9.8) — CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename

mednvdPublished 2026-07-31

CVE-2026-63223 CVSS: 9.8 CRITICAL Published: 2026-07-31T06:16:32.297

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-ena

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63223