CVE-2026-79752
- EPSS 0.46%
- Veröffentlicht 17.09.2026 14:49:56
- Zuletzt bearbeitet 30.09.2026 17:43:24
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php acce...
CVE-2026-77634
- EPSS 0.31%
- Veröffentlicht 24.08.2026 20:33:46
- Zuletzt bearbeitet 09.09.2026 21:06:39
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes remove...
CVE-2026-77635
- EPSS 0.29%
- Veröffentlicht 24.08.2026 20:30:34
- Zuletzt bearbeitet 09.09.2026 21:06:39
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to...
CVE-2026-55590
- EPSS 0.28%
- Veröffentlicht 09.07.2026 18:55:30
- Zuletzt bearbeitet 13.07.2026 17:09:24
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets ...
CVE-2026-48820
- EPSS 0.26%
- Veröffentlicht 17.06.2026 21:19:44
- Zuletzt bearbeitet 23.06.2026 15:44:39
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is wi...
CVE-2026-23643
- EPSS 0.26%
- Veröffentlicht 16.01.2026 20:38:45
- Zuletzt bearbeitet 23.02.2026 20:51:11
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
CVE-2023-22727
- EPSS 0.86%
- Veröffentlicht 17.01.2023 21:15:16
- Zuletzt bearbeitet 21.11.2024 07:45:18
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fix...
CVE-2020-35239
- EPSS 0.6%
- Veröffentlicht 26.01.2021 18:15:53
- Zuletzt bearbeitet 15.01.2025 17:44:05
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of reque...
CVE-2019-11458
- EPSS 2%
- Veröffentlicht 08.05.2019 18:29:00
- Zuletzt bearbeitet 15.01.2025 17:44:05
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.
CVE-2016-4793
- EPSS 5.15%
- Veröffentlicht 23.01.2017 21:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.