Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-55590
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, …
Cakephp
2.11.1 / 3.3.6+
MEDIUM 5.4
CVE-2026-23643
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query strin…
Cakephp
5.2.12+
CRITICAL 9.8
CVE-2023-22727
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` meth…
Cakephp
4.2.12 / 4.3.11+
HIGH 8.8
CVE-2020-35239
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CS…
Cakephp
after 4.1.3
HIGH 7.5
CVE-2019-11458
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwr…
Cakephp
Patch available
HIGH 7.5
CVE-2016-4793EPSS 5%
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
Cakephp
after 3.2.4
HIGH 8.8
CVE-2015-8379
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
Cakephp
Patch available
MEDIUM 5.0
CVE-2011-3712
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …
Cakephp
No fix yet
MEDIUM 5.0
CVE-2006-5031EPSS 7%
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read…
Cakephp
after 1.1.7.3363