Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Markstory

#49654of 56,337
5.4Total CVSS
Vulnerabilities · 1
PT-2026-3322
5.4
2026-01-16
Cakephp · Cakephp · CVE-2026-23643
**Name of the Vulnerable Software and Affected Versions** CakePHP versions prior to 5.2.12 CakePHP versions prior to 5.3.1 **Description** The `PaginatorHelper::limitControl()` method is susceptible to cross-site scripting through manipulation of query string parameters. If unable to upgrade, avoid using `Paginator::limitControl()`. **Recommendations** Upgrade to CakePHP version 5.2.12 or later. Upgrade to CakePHP version 5.3.1 or later.