Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2026-23643
CVE-2026-23643
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
Published Jan 19, 2026
https://github.com/cakephp/cakephp/issues/19172
https://github.com/advisories/GHSA-qh8m-9qxx-53m5
CVSS Score
Medium
5.3
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
composer
cakephp/cakephp
5.2.10
composer
cakephp/cakephp
5.2.11
composer
cakephp/cakephp
5.3.0
1-3 of 3
CVE-2026-23643 | Components Impacted | Sonatype Guide | Sonatype Guide