CVE-2026-63221 PUBLISHED

CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions

Assigner: GitHub_M
Reserved: 15.07.2026 Published: 31.07.2026 Updated: 31.07.2026

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed in version 4.7.4.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CVSS Score: 9.4

Product Status

Vendor codeigniter4
Product CodeIgniter4
Versions
  • Version >= 4.3.0, < 4.7.4 is affected

References

Problem Types

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE