CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
DebugKit: MailPreview contains unsafe reflection
CakePHP: Potential Authentication bypass with CookieAuthenticator
CakePHP: SmtpTransport vulnerable to CRLF header injection
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
CakePHP: Open redirect weakness via backslash bypass
CakePHP: View::element() is missing a path containment check
CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting
Database Query::offset() and limit() vulnerable to SQL injection in cakephp
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks…
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon…
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error mess…
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal C…
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary…
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via…
Showing 1 to 18 CVEs · page 1