THREAT OPS › Threat News › [NVD] CVE-2026-63223 (CRITICAL 9.8) — CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename
[NVD] CVE-2026-63223 (CRITICAL 9.8) — CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename
CVE-2026-63223 CVSS: 9.8 CRITICAL Published: 2026-07-31T06:16:32.297
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-ena
Indicators of compromise
- CVE-2026-63223cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63223