Skip to content
Noroxi

cakephp records

11 published records for vendor cakephp.

All records

11 records
  • The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to mo

    HighCVSS 7.5WeaponizedEPSS 55%

    cakephp · cakephpJan 14, 2011

  • Database Query::offset() and limit() vulnerable to SQL injection in cakephp

    CriticalCVSS 9.8No exploitEPSS 1%

    cakephp · cakephpJan 17, 2023

  • CVE-2015-8379
    35Monitor

    CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

    HighCVSS 8.8No exploitEPSS 1%

    cakephp · cakephpJan 26, 2016

  • A vulnerability exists in CakePHP versions 4.0.x through 4.1.3.

    HighCVSS 8.8No exploitEPSS 1%

    cakephp · cakephpJan 26, 2021

  • CVE-2016-4793
    32Monitor

    The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

    HighCVSS 7.5Proof of conceptEPSS 5%

    cakephp · cakephpJan 23, 2017

  • An issue was discovered in SmtpTransport in CakePHP 3.7.6.

    HighCVSS 7.5No exploitEPSS 2%

    cakephp · cakephpMay 8, 2019

  • CVE-2006-5031
    22Monitor

    Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attacker

    MediumCVSS 5.0Proof of conceptEPSS 8%

    cakephp · cakephpSep 27, 2006

  • CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting

    MediumCVSS 5.4No exploitEPSS 0%

    cakephp · cakephpJan 16, 2026

  • CVE-2011-3712
    20Monitor

    CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa

    MediumCVSS 5.0No exploitEPSS 2%

    cakephp · cakephpSep 23, 2011

  • CakePHP: Open redirect weakness via backslash bypass

    MediumCVSS 5.1No exploitEPSS 0%

    cakephp · cakephpJul 9, 2026

  • CVE-2006-4067
    17Monitor

    Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web

    MediumCVSS 4.3No exploitEPSS 1%

    cakephp · cakephpAug 9, 2006