CVE-2018-12071: Codeigniter
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
Affected products
- Codeigniter Codeigniter: before 3.1.9 (fixed in 3.1.9)
Published 2018-06-17. Last modified 2026-06-17.