CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-79752 CRITICAL

CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection

CVSS 9.2 EPSS 0.62% Sep 17, 2026
CVE-2026-54713 LOW

CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions

CVSS 3.7 EPSS 0.46% Aug 27, 2026
CVE-2026-54614 MEDIUM

DebugKit: MailPreview contains unsafe reflection

CVSS 4.3 EPSS 0.54% Aug 26, 2026
CVE-2026-77337 CRITICAL

CakePHP: Potential Authentication bypass with CookieAuthenticator

CVSS 9.1 EPSS 0.70% Aug 24, 2026
CVE-2026-77634 HIGH

CakePHP: SmtpTransport vulnerable to CRLF header injection

CVSS 8.2 EPSS 0.54% Aug 24, 2026
CVE-2026-77635 CRITICAL

CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver

CVSS 9.2 EPSS 0.49% Aug 24, 2026
CVE-2026-55590 MEDIUM

CakePHP: Open redirect weakness via backslash bypass

CVSS 5.1 EPSS 0.49% Jul 9, 2026
CVE-2026-48820 MEDIUM

CakePHP: View::element() is missing a path containment check

CVSS 6.3 EPSS 0.37% Jun 17, 2026
CVE-2026-23643 MEDIUM

CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting

CVSS 5.4 EPSS 0.29% Jan 16, 2026
CVE-2023-22727 CRITICAL

Database Query::offset() and limit() vulnerable to SQL injection in cakephp

CVSS 9.8 EPSS 0.86% Jan 17, 2023
CVE-2020-35239 HIGH

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks…

CVSS 8.8 EPSS 0.60% Jan 20, 2021
CVE-2019-11458 HIGH

An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon…

CVSS 7.5 EPSS 2.00% May 8, 2019
CVE-2016-4793 HIGH

The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

CVSS 7.5 EPSS 5.15% Jan 23, 2017
CVE-2015-8379 HIGH

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

CVSS 8.8 EPSS 1.40% Jan 26, 2016
CVE-2011-3712 MEDIUM

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error mess…

CVSS 5.0 EPSS 1.58% Sep 23, 2011
CVE-2010-4335 HIGH

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal C…

CVSS 7.5 EPSS 55.20% Jan 14, 2011
CVE-2006-5031 MEDIUM

Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary…

CVSS 5.0 EPSS 7.53% Sep 27, 2006
CVE-2006-4067 MEDIUM

Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 6.5 EPSS 1.21% Aug 10, 2006

Showing 1 to 18 CVEs · page 1