THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c9w5-rwh3-7pm9 (critical) — CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions

[GHSA] GHSA-c9w5-rwh3-7pm9 (critical) — CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions

medgithub_advisoriesPublished 2026-08-07

GHSA-c9w5-rwh3-7pm9 Severity: critical CVE: CVE-2026-63221

CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions

### Impact A SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause are substituted directly into the generated SQ

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c9w5-rwh3-7pm9