VYPR
Vendor

Cakephp

Products
3
CVEs
20
Across products
20
Status
Private

Products

3

Recent CVEs

20
  • CVE-2023-22727CriJan 17, 2023
    risk 0.57cvss 9.8epss 0.01

    CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10.…

  • CVE-2020-35239HigJan 26, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP…

  • CVE-2026-79752CriSep 17, 2026
    risk 0.53cvss —epss 0.01

    CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType,…

  • CVE-2026-77635CriAug 24, 2026
    risk 0.53cvss —epss 0.00

    CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This…

  • CVE-2012-4399HigOct 9, 2012
    risk 0.53cvss 7.5epss 0.12

    The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

  • CVE-2026-77337CriAug 24, 2026
    risk 0.52cvss —epss 0.01

    CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when…

  • CVE-2015-8379HigJan 26, 2016
    risk 0.50cvss 8.8epss 0.01

    CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

  • CVE-2026-77634HigAug 24, 2026
    risk 0.46cvss —epss 0.01

    CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection…

  • CVE-2016-4793HigJan 23, 2017
    risk 0.45cvss 7.5epss 0.05

    The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

  • CVE-2019-11458HigMay 8, 2019
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.

  • CVE-2026-48820MedJun 17, 2026
    risk 0.41cvss —epss 0.00

    CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin…

  • CVE-2026-55590MedJul 9, 2026
    risk 0.33cvss 6.1epss 0.00

    CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled…

  • CVE-2026-23643MedJan 16, 2026
    risk 0.28cvss 5.4epss 0.00

    CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.

  • CVE-2020-15400MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.00

    CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

  • CVE-2026-54614MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.01

    DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className()…

  • CVE-2026-54713LowAug 27, 2026
    risk 0.17cvss 3.7epss 0.00

    CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An…

  • CVE-2006-5031Sep 27, 2006
    risk 0.04cvss —epss 0.08

    Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename.

  • CVE-2011-3712Sep 23, 2011
    risk 0.00cvss —epss 0.02

    CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.

  • CVE-2010-4335Jan 14, 2011
    risk 0.00cvss —epss 0.55

    The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize…

  • CVE-2006-4067Aug 10, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from…