5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Description
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
Basic Information
ID
CVE-2026-23643
Source
GitHub_M
Published
Jan 16, 2026 at 20:38
Modified
Jan 16, 2026 at 21:21
Affected Product
Vendor
cakephp
Product
cakephp
Version
>= 5.2.10, < 5.2.12
Affected Versions
cakephp cakephp >= 5.2.10, < 5.2.12
cakephp cakephp >= 5.3.0, < 5.3.1
cakephp cakephp >= 5.3.0, < 5.3.1
CWE Classification
References
- github.com /cakephp/cakephp/security/advisories/GHSA-qh8m-9qxx-53m5
- github.com /cakephp/cakephp/issues/19172
- github.com /cakephp/cakephp/commit/c842e7f45d85696e6527d8991dd72f525ced955f
- bakery.cakephp.org /2026/01/14/cakephp_5212.html
- github.com /cakephp/cakephp/releases/tag/5.2.12
- github.com /cakephp/cakephp/releases/tag/5.3.1