cakephp records
11 published records for vendor cakephp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2010-4335Weaponized | The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mocakephp · cakephp · CWE-20 | High7.5 | — | 55.2% | Jan 14, 2011 |
39Monitor | CVE-2023-22727No exploit | Database Query::offset() and limit() vulnerable to SQL injection in cakephpcakephp · cakephp · CWE-89 | Critical9.8 | — | 0.9% | Jan 17, 2023 |
35Monitor | CVE-2015-8379No exploit | CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.cakephp · cakephp · CWE-352 | High8.8 | — | 1.4% | Jan 26, 2016 |
35Monitor | CVE-2020-35239No exploit | A vulnerability exists in CakePHP versions 4.0.x through 4.1.3.cakephp · cakephp · CWE-352 | High8.8 | — | 0.6% | Jan 26, 2021 |
32Monitor | CVE-2016-4793Proof of concept | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.cakephp · cakephp · CWE-20 | High7.5 | — | 5.1% | Jan 23, 2017 |
31Monitor | CVE-2019-11458No exploit | An issue was discovered in SmtpTransport in CakePHP 3.7.6.cakephp · cakephp · CWE-502 | High7.5 | — | 2.0% | May 8, 2019 |
22Monitor | CVE-2006-5031Proof of concept | Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackercakephp · cakephp · CWE-22 | Medium5.0 | — | 7.5% | Sep 27, 2006 |
21Monitor | CVE-2026-23643No exploit | CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scriptingcakephp · cakephp · CWE-79 | Medium5.4 | — | 0.3% | Jan 16, 2026 |
20Monitor | CVE-2011-3712No exploit | CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pacakephp · cakephp · CWE-200 | Medium5.0 | — | 1.6% | Sep 23, 2011 |
20Monitor | CVE-2026-55590No exploit | CakePHP: Open redirect weakness via backslash bypasscakephp · cakephp · CWE-601 | Medium5.1 | — | 0.5% | Jul 9, 2026 |
17Monitor | CVE-2006-4067No exploit | Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary webcakephp · cakephp · CWE-79 | Medium4.3 | — | 1.2% | Aug 9, 2006 |
- CVE-2010-433547Plan
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mo
HighCVSS 7.5WeaponizedEPSS 55%cakephp · cakephpJan 14, 2011
- CVE-2023-2272739Monitor
Database Query::offset() and limit() vulnerable to SQL injection in cakephp
CriticalCVSS 9.8No exploitEPSS 1%cakephp · cakephpJan 17, 2023
- CVE-2015-837935Monitor
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
HighCVSS 8.8No exploitEPSS 1%cakephp · cakephpJan 26, 2016
- CVE-2020-3523935Monitor
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3.
HighCVSS 8.8No exploitEPSS 1%cakephp · cakephpJan 26, 2021
- CVE-2016-479332Monitor
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
HighCVSS 7.5Proof of conceptEPSS 5%cakephp · cakephpJan 23, 2017
- CVE-2019-1145831Monitor
An issue was discovered in SmtpTransport in CakePHP 3.7.6.
HighCVSS 7.5No exploitEPSS 2%cakephp · cakephpMay 8, 2019
- CVE-2006-503122Monitor
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attacker
MediumCVSS 5.0Proof of conceptEPSS 8%cakephp · cakephpSep 27, 2006
- CVE-2026-2364321Monitor
CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting
MediumCVSS 5.4No exploitEPSS 0%cakephp · cakephpJan 16, 2026
- CVE-2011-371220Monitor
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa
MediumCVSS 5.0No exploitEPSS 2%cakephp · cakephpSep 23, 2011
- CVE-2026-5559020Monitor
CakePHP: Open redirect weakness via backslash bypass
MediumCVSS 5.1No exploitEPSS 0%cakephp · cakephpJul 9, 2026
- CVE-2006-406717Monitor
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web
MediumCVSS 4.3No exploitEPSS 1%cakephp · cakephpAug 9, 2006