CakePHP 5.4.2 presents a very strong dependency-health profile. It is a mature, stable, actively released package with 458 releases over more than 12 years, 32 releases in the last 12 months, recent repository activity, 12 active contributors, organizational backing, comprehensive tests and documentation, explicit MIT licensing, and strong repository and CI security hygiene. The missing changelog is a minor transparency gap, but GitHub Releases, extensive repository scaffolding, and sustained maintenance substantially compensate for it.
98%
Total Score
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-625900 cakephp/cakephp is vulnerable to CRLF Injection in versions 4.5.0 - 4.5.11, 4.6.0 - 4.6.4, 5.0.0 - 5.1.8, 5.2.0 - 5.2.13 and 5.3.0 - 5.3.6. | 4.5.0 - 4.5.114.6.0 - 4.6.45.0.0 - 5.1.8 +2 more | Medium |
AIKIDO-2026-102920 cakephp/cakephp is vulnerable to SQL Injection in versions 5.1.0 - 5.1.9, 5.2.0 - 5.2.14 and 5.3.0 - 5.3.6. | 5.1.0 - 5.1.95.2.0 - 5.2.145.3.0 - 5.3.6 | High |
CVE-2026-48820 cakephp/cakephp is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 5.3.0 - 5.3.6, 5.2.0 - 5.2.13, 5.0.0 - 5.1.7, 4.6.0 - 4.6.4 and 0.0.0 - 4.5.11. | 0.0.0 - 4.5.114.6.0 - 4.6.45.0.0 - 5.1.7 +2 more | Medium |
CVE-2026-23643 cakephp/cakephp is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.2.10 - 5.2.12 and 5.3.0 - 5.3.0. | 5.2.10 - 5.2.125.3.0 - 5.3.0 | Medium |
AIKIDO-2025-10653 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. cakephp/cakephp is vulnerable to Improper Authorization in versions 3.2.6 - 5.2.7. | 3.2.6 - 5.2.7 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/link Version ^2.0 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
cakephp/chronos Version ^3.3 | — | — |
psr/http-client Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.