codeigniter4/framework
php · codeigniter4/frameworkCritical
CodeIgniter 4 ext_in Validation Bypass via MIME Extension
The `ext_in` upload validation rule used the MIME-derived guessed extension instead of the client-provided filename extension, all
12 Jun 2026 · act now