CVE-2026-23643: Cakephp
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
Affected products
- Cakephp Cakephp: from 5.2.10, before 5.2.12 (fixed in 5.2.12); version 5.3.0 only
Published 2026-01-16. Last modified 2026-06-17.