Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cakephp

First CVE: Aug 10, 2006Active for: 20 yearsTotal CVEs: 11
47.5
VTI Score
High

CakePHP is a widely adopted open-source web application framework whose modest but prominent vulnerability footprint centers on input handling and state management weaknesses endemic to web applications. The framework's disclosures cluster around cross-site request forgery, improper input validation, cross-site scripting, untrusted deserialization, and information disclosure, reflecting the request-processing and template-rendering surface area inherent to application frameworks; vulnerabilities affecting the framework frequently acquire public exploit code. Defenders should treat framework updates as broadly applicable to downstream applications and prioritize patching where CakePHP-based systems handle sensitive data; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cakephp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 10, 2006
19 years ago
Most Recent CVE
Jul 9, 2026
16 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4335HIGH
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute
Jan 14, 20117.572NOYES
CVE-2016-4793HIGH
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
Jan 23, 20177.537NOYES
CVE-2023-22727CRITICAL
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injec
Jan 17, 20239.831NONO
CVE-2026-55590MEDIUM
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method c
Jul 9, 20266.130NONO
CVE-2019-11458HIGH
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.
May 8, 20197.525NONO
CVE-2006-5031MEDIUM
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot
Sep 27, 20065.025NOYES
CVE-2020-35239HIGH
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP
Jan 26, 20218.822NONO
CVE-2015-8379HIGH
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
Jan 26, 20168.822NONO
CVE-2026-23643MEDIUM
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This
Jan 16, 20265.420NONO
CVE-2011-3712MEDIUM
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated
Sep 23, 20115.017NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
45%
45%
9%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (63.6%)
Unknown4 (36.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High0 (0.0%)
Unknown4 (36.4%)
User Interaction
None3 (27.3%)
Unknown4 (36.4%)
Required4 (36.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (63.6%)
Unknown4 (36.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
27.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cakephp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cakephp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cakephp's Products

View all 3 CNAs →

Top CWEs