CakePHP is a widely adopted open-source web application framework whose modest but prominent vulnerability footprint centers on input handling and state management weaknesses endemic to web applications. The framework's disclosures cluster around cross-site request forgery, improper input validation, cross-site scripting, untrusted deserialization, and information disclosure, reflecting the request-processing and template-rendering surface area inherent to application frameworks; vulnerabilities affecting the framework frequently acquire public exploit code. Defenders should treat framework updates as broadly applicable to downstream applications and prioritize patching where CakePHP-based systems handle sensitive data; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cakephp over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4335HIGH The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute | Jan 14, 2011 | 7.5 | 72 | NO | YES |
CVE-2016-4793HIGH The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header. | Jan 23, 2017 | 7.5 | 37 | NO | YES |
CVE-2023-22727CRITICAL CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injec | Jan 17, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-55590MEDIUM CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method c | Jul 9, 2026 | 6.1 | 30 | NO | NO |
CVE-2019-11458HIGH An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction. | May 8, 2019 | 7.5 | 25 | NO | NO |
CVE-2006-5031MEDIUM Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot | Sep 27, 2006 | 5.0 | 25 | NO | YES |
CVE-2020-35239HIGH A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP | Jan 26, 2021 | 8.8 | 22 | NO | NO |
CVE-2015-8379HIGH CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter. | Jan 26, 2016 | 8.8 | 22 | NO | NO |
CVE-2026-23643MEDIUM CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This | Jan 16, 2026 | 5.4 | 20 | NO | NO |
CVE-2011-3712MEDIUM CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated | Sep 23, 2011 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cakephp.
Media articles that mention a CVE ID that affects a product developed by Cakephp — matched by CVE ID, not by vendor name.