cakephp kayıtları
cakephp üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %9,1
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2010-4335Silahlaştırılmış | The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mocakephp · cakephp · CWE-20 | Yüksek7,5 | — | %55,2 | 14 Oca 2011 |
39İzleyin | CVE-2023-22727İstismar yok | Database Query::offset() and limit() vulnerable to SQL injection in cakephpcakephp · cakephp · CWE-89 | Kritik9,8 | — | %0,9 | 17 Oca 2023 |
35İzleyin | CVE-2015-8379İstismar yok | CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.cakephp · cakephp · CWE-352 | Yüksek8,8 | — | %1,4 | 26 Oca 2016 |
35İzleyin | CVE-2020-35239İstismar yok | A vulnerability exists in CakePHP versions 4.0.x through 4.1.3.cakephp · cakephp · CWE-352 | Yüksek8,8 | — | %0,6 | 26 Oca 2021 |
32İzleyin | CVE-2016-4793Kavram kanıtı | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.cakephp · cakephp · CWE-20 | Yüksek7,5 | — | %5,1 | 23 Oca 2017 |
31İzleyin | CVE-2019-11458İstismar yok | An issue was discovered in SmtpTransport in CakePHP 3.7.6.cakephp · cakephp · CWE-502 | Yüksek7,5 | — | %2,0 | 8 May 2019 |
22İzleyin | CVE-2006-5031Kavram kanıtı | Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackercakephp · cakephp · CWE-22 | Orta5,0 | — | %7,5 | 27 Eyl 2006 |
21İzleyin | CVE-2026-23643İstismar yok | CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scriptingcakephp · cakephp · CWE-79 | Orta5,4 | — | %0,3 | 16 Oca 2026 |
20İzleyin | CVE-2011-3712İstismar yok | CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pacakephp · cakephp · CWE-200 | Orta5,0 | — | %1,6 | 23 Eyl 2011 |
20İzleyin | CVE-2026-55590İstismar yok | CakePHP: Open redirect weakness via backslash bypasscakephp · cakephp · CWE-601 | Orta5,1 | — | %0,5 | 9 Tem 2026 |
17İzleyin | CVE-2006-4067İstismar yok | Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary webcakephp · cakephp · CWE-79 | Orta4,3 | — | %1,2 | 9 Ağu 2006 |
- CVE-2010-433547Planlayın
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mo
YüksekCVSS 7,5SilahlaştırılmışEPSS %55cakephp · cakephp14 Oca 2011
- CVE-2023-2272739İzleyin
Database Query::offset() and limit() vulnerable to SQL injection in cakephp
KritikCVSS 9,8İstismar yokEPSS %1cakephp · cakephp17 Oca 2023
- CVE-2015-837935İzleyin
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
YüksekCVSS 8,8İstismar yokEPSS %1cakephp · cakephp26 Oca 2016
- CVE-2020-3523935İzleyin
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3.
YüksekCVSS 8,8İstismar yokEPSS %1cakephp · cakephp26 Oca 2021
- CVE-2016-479332İzleyin
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
YüksekCVSS 7,5Kavram kanıtıEPSS %5cakephp · cakephp23 Oca 2017
- CVE-2019-1145831İzleyin
An issue was discovered in SmtpTransport in CakePHP 3.7.6.
YüksekCVSS 7,5İstismar yokEPSS %2cakephp · cakephp8 May 2019
- CVE-2006-503122İzleyin
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attacker
OrtaCVSS 5,0Kavram kanıtıEPSS %8cakephp · cakephp27 Eyl 2006
- CVE-2026-2364321İzleyin
CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting
OrtaCVSS 5,4İstismar yokEPSS %0cakephp · cakephp16 Oca 2026
- CVE-2011-371220İzleyin
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa
OrtaCVSS 5,0İstismar yokEPSS %2cakephp · cakephp23 Eyl 2011
- CVE-2026-5559020İzleyin
CakePHP: Open redirect weakness via backslash bypass
OrtaCVSS 5,1İstismar yokEPSS %0cakephp · cakephp9 Tem 2026
- CVE-2006-406717İzleyin
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web
OrtaCVSS 4,3İstismar yokEPSS %1cakephp · cakephp9 Ağu 2006