Critical severity9.4NVD Advisory· Published Jul 31, 2026· Updated Sep 8, 2026
CVE-2026-63221
CVE-2026-63221
Description
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed in version 4.7.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
codeigniter4/frameworkPackagist | >= 4.3.0, < 4.7.4 | 4.7.4 |
Affected products
1- Range: 4.3.0 - 4.7.3
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-c9w5-rwh3-7pm9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-63221ghsaADVISORY
- github.com/codeigniter4/CodeIgniter4/commit/f5e463b9a3e986389ce285963e51a7f1fab6559fnvdWEB
- github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4nvdWEB
- github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9nvdWEB
News mentions
0No linked articles in our index yet.