Cakephp/cakephp
This hub aggregates every CVE we track for Cakephp/cakephp, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
18
CVEs tracked
1
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6MEDIUM5CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Cakephp/cakephp.
- CVE-2026-23643CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting5.4
- GHSA-xwhj-pqcg-8rcrCakePHP vulnerable to Cross-site Scripting in some development error pages
- GHSA-p76f-wr22-4rv6CakePHP vulnerable to Remote File Inclusion through View template name manipulation
- GHSA-6hg4-vp5q-47mwCakePHP allows direct access of prefixed controller actions
- GHSA-q79m-c546-2g63CakePHP vulnerable to Denial of Service attack through XML payloads
- GHSA-j9q2-f9q7-jhgqCakePHP SecurityComponent cross form submission issue
- GHSA-829q-v5g8-hhxcCakePHP has incorrect Cross-Site Request Forgery validation
- CVE-2023-22727Database Query::offset() and limit() vulnerable to SQL injection in cakephp9.8
- CVE-2020-35239A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to...8.8
- CVE-2020-15400CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.4.3
- CVE-2019-11458An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.7.5
- CVE-2016-4793The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.7.5
- CVE-2015-8379CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.8.8
- CVE-2012-4399The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XX...7.5
- CVE-2011-3712CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php...5.0
Product normalization is registry-driven with AI assist and human review. How it works