İçeriğe atla
Noroxi

cakephp kayıtları

cakephp üreticisine ait 11 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %9,1
Pre-auth RCE
1
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

11 kayıt
  • CVE-2010-4335
    47Planlayın

    The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mo

    YüksekCVSS 7,5SilahlaştırılmışEPSS %55

    cakephp · cakephp14 Oca 2011

  • CVE-2023-22727
    39İzleyin

    Database Query::offset() and limit() vulnerable to SQL injection in cakephp

    KritikCVSS 9,8İstismar yokEPSS %1

    cakephp · cakephp17 Oca 2023

  • CVE-2015-8379
    35İzleyin

    CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

    YüksekCVSS 8,8İstismar yokEPSS %1

    cakephp · cakephp26 Oca 2016

  • CVE-2020-35239
    35İzleyin

    A vulnerability exists in CakePHP versions 4.0.x through 4.1.3.

    YüksekCVSS 8,8İstismar yokEPSS %1

    cakephp · cakephp26 Oca 2021

  • CVE-2016-4793
    32İzleyin

    The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    cakephp · cakephp23 Oca 2017

  • CVE-2019-11458
    31İzleyin

    An issue was discovered in SmtpTransport in CakePHP 3.7.6.

    YüksekCVSS 7,5İstismar yokEPSS %2

    cakephp · cakephp8 May 2019

  • CVE-2006-5031
    22İzleyin

    Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attacker

    OrtaCVSS 5,0Kavram kanıtıEPSS %8

    cakephp · cakephp27 Eyl 2006

  • CVE-2026-23643
    21İzleyin

    CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting

    OrtaCVSS 5,4İstismar yokEPSS %0

    cakephp · cakephp16 Oca 2026

  • CVE-2011-3712
    20İzleyin

    CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa

    OrtaCVSS 5,0İstismar yokEPSS %2

    cakephp · cakephp23 Eyl 2011

  • CVE-2026-55590
    20İzleyin

    CakePHP: Open redirect weakness via backslash bypass

    OrtaCVSS 5,1İstismar yokEPSS %0

    cakephp · cakephp9 Tem 2026

  • CVE-2006-4067
    17İzleyin

    Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web

    OrtaCVSS 4,3İstismar yokEPSS %1

    cakephp · cakephp9 Ağu 2006