Cakefoundation / Cakephp
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-15400 | CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS. | MEDIUM | 4.3 | Jun 30, 2020 |
| CVE-2012-4399 | The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity refe… | HIGH | 7.5 | Oct 9, 2012 |
| CVE-2010-4335 | The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal C… | HIGH | 7.5 | Jan 14, 2011 |
Showing 1 to 3 of 3 CVEs