cakefoundation records
3 published records for vendor cakefoundation.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 33.3%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2010-4335Weaponized | The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mocakephp · cakephp · CWE-20 | High7.5 | — | 55.2% | Jan 14, 2011 |
34Monitor | CVE-2012-4399Proof of concept | The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing ecakefoundation · cakephp · CWE-611 | High7.5 | — | 12.1% | Oct 9, 2012 |
17Monitor | CVE-2020-15400No exploit | CakePHP before 4.0.6 mishandles CSRF token generation.cakefoundation · cakephp · CWE-79 | Medium4.3 | — | 0.4% | Jun 30, 2020 |
- CVE-2010-433547Plan
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mo
HighCVSS 7.5WeaponizedEPSS 55%cakephp · cakephpJan 14, 2011
- CVE-2012-439934Monitor
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing e
HighCVSS 7.5Proof of conceptEPSS 12%cakefoundation · cakephpOct 9, 2012
- CVE-2020-1540017Monitor
CakePHP before 4.0.6 mishandles CSRF token generation.
MediumCVSS 4.3No exploitEPSS 0%cakefoundation · cakephpJun 30, 2020