The CakePHP framework
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-23643 cakephp/cakephp is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.2.10 - 5.2.12 and 5.3.0 - 5.3.0. | 5.2.10 - 5.2.125.3.0 - 5.3.0 | Medium |
AIKIDO-2025-10653 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. cakephp/cakephp is vulnerable to Improper Authorization in versions 3.2.6 - 5.2.7. | 3.2.6 - 5.2.7 | Medium |
AIKIDO-2025-10005 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. cakephp/cakephp is vulnerable to Open Redirect in versions 5.0.0 - 5.1.2 and 3.0.0 - 4.5.8. | 3.0.0 - 4.5.85.0.0 - 5.1.2 | Medium |
AIKIDO-2024-10535 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. cakephp/cakephp is vulnerable to Improper Encoding or Escaping of Output in versions 4.0.0 - 5.1.3. | 4.0.0 - 5.1.3 | Low |
CVE-2023-22727 cakephp/cakephp is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 4.2.0 - 4.2.12, 4.3.0 - 4.3.11 and 4.4.0 - 4.4.10. | 4.2.0 - 4.2.124.3.0 - 4.3.114.4.0 - 4.4.10 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
cakephp/chronos Version ^3.3 | — | — |
psr/http-client Version ^1.0.2 | — | — |
league/container Version ^5.1 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant