Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions
CVE-2026-63221
Description
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed in version 4.7.4.
Affected products
1- Range: 4.3.0 - 4.7.3
Patches
Vulnerability mechanics
References
3- github.com/codeigniter4/CodeIgniter4/commit/f5e463b9a3e986389ce285963e51a7f1fab6559fmitrex_refsource_MISC
- github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4mitrex_refsource_MISC
- github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.