cakephp
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting cakephp.
- CVE-2026-79752CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
- CVE-2026-54713CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions3.7
- CVE-2026-54614DebugKit: MailPreview contains unsafe reflection4.3
- CVE-2026-77337CakePHP: Potential Authentication bypass with CookieAuthenticator
- CVE-2026-77634CakePHP: SmtpTransport vulnerable to CRLF header injection
- CVE-2026-77635CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
- CVE-2026-55590CakePHP: Open redirect weakness via backslash bypass6.1
- CVE-2026-48820CakePHP: View::element() is missing a path containment check
- CVE-2026-23643CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting5.4
- CVE-2023-22727Database Query::offset() and limit() vulnerable to SQL injection in cakephp9.8
- CVE-2020-35239A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to...8.8
- CVE-2019-11458An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.7.5
- CVE-2016-4793The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.7.5
- CVE-2015-8379CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.8.8
- CVE-2011-3712CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php...5.0