Skip to content
Noroxi

cakefoundation records

3 published records for vendor cakefoundation.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 33.3%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

3 records
  • The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mo

    HighCVSS 7.5WeaponizedEPSS 55%

    cakephp · cakephpJan 14, 2011

  • CVE-2012-4399
    34Monitor

    The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing e

    HighCVSS 7.5Proof of conceptEPSS 12%

    cakefoundation · cakephpOct 9, 2012

  • CakePHP before 4.0.6 mishandles CSRF token generation.

    MediumCVSS 4.3No exploitEPSS 0%

    cakefoundation · cakephpJun 30, 2020