Home/Product/cakephp
Product

cakephp

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-23643
>= 5.2.10 and < 5.2.12
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerabil
5.4MEDIUM
CVE-2023-22727
>= 4.2.0 and < 4.2.12
CakePHP is a development framework for PHP web apps. In affected versions the Cake\Database\Query::limit() and `Cake\Database\Qu
9.8CRITICAL
CVE-2020-35239
>= 4.0.0 and <= 4.1.3
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override para
8.8HIGH
CVE-2020-15400
< 4.0.6
CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
4.3MEDIUM
CVE-2019-11458
all versions
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger ar
7.5HIGH
CVE-2016-4793
<= 3.2.4
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
7.5HIGH
CVE-2015-8379
all versions
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
8.8HIGH
CVE-2012-4399
>= 2.1.0 and < 2.1.5
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data co
7.5HIGH
CVE-2011-3712
all versions
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the insta
CVE-2010-4335
all versions
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attac
CVE-2006-5031
<= 1.1.7.3363
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remot
CVE-2006-4067
<= 1.1.6.3264
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arb
threatengine.sh