All 5 CVE vulnerabilities found in cakephp, with AI-generated Chinese analysis, references, and POCs.
Vendor: cakephp
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-77634 | CakePHP: SmtpTransport vulnerable to CRLF header injection CWE-93 | 8.2 | High | 2026-08-24 |
| CVE-2026-77635 | CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver CWE-89 | 9.2 | Critical | 2026-08-24 |
| CVE-2026-48820 | CakePHP: View::element() is missing a path containment check CWE-98 | - | - | 2026-06-17 |
| CVE-2026-23643 | CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting CWE-79 | 5.4 | Medium | 2026-01-16 |
| CVE-2023-22727 | Database Query::offset() and limit() vulnerable to SQL injection in cakephp CWE-89 | 9.8 | Critical | 2023-01-17 |
All 5 known CVE vulnerabilities affecting cakephp with full Chinese analysis, references, and POCs where available.