CVE-2018-12071: Codeigniter

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.

Affected products

Published 2018-06-17. Last modified 2026-06-17.