CVE-2015-5725: Codeigniter
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.
Affected products
- Codeigniter Codeigniter: before 2.2.4 (fixed in 2.2.4)
Published 2018-02-21. Last modified 2026-06-17.