Product
cakephp
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-23643
CVE-2023-22727
CVE-2020-35239
CVE-2020-15400
CVE-2019-11458
CVE-2016-4793
CVE-2015-8379
CVE-2012-4399
CVE-2011-3712
CVE-2010-4335
CVE-2006-5031
CVE-2006-4067
>= 5.2.10 and < 5.2.12
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerabil
>= 4.2.0 and < 4.2.12
CakePHP is a development framework for PHP web apps. In affected versions the
Cake\Database\Query::limit() and `Cake\Database\Qu>= 4.0.0 and <= 4.1.3
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override para
< 4.0.6
CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
all versions
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger ar
<= 3.2.4
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
all versions
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
>= 2.1.0 and < 2.1.5
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data co
all versions
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the insta
all versions
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attac
<= 1.1.7.3363
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remot
<= 1.1.6.3264
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arb