CVE-2026-23643
EUVD-2026-286116.01.2026, 21:15
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cakephp | cakephp | 5.2.10 ≤ 𝑥 < 5.2.12 |
| cakephp | cakephp | 5.3.0 |
𝑥
= Vulnerable software versions
References