Skip to main content

Vendor archive

cakefoundation CVEs

Beta · best-effort

3 CVEs tagged to vendor cakefoundation0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2012-4399

Published Oct 9, 2012

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4335

Published Jan 14, 2011

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execut…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1