CVE-2014-8686: Codeigniter

Critical severity, CVSS 9.8. EPSS: 37.2% chance of exploitation in the next 30 days.

CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.

Affected products

Published 2017-09-19. Last modified 2026-06-17.