PT-2026-3322 · Cakephp · Cakephp

·

CVE-2026-23643

·

Published

2026-01-16

·

Updated

2026-01-16

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CakePHP versions prior to 5.2.12 CakePHP versions prior to 5.3.1
Description The PaginatorHelper::limitControl() method is susceptible to cross-site scripting through manipulation of query string parameters. If unable to upgrade, avoid using Paginator::limitControl().
Recommendations Upgrade to CakePHP version 5.2.12 or later. Upgrade to CakePHP version 5.3.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23643
GHSA-QH8M-9QXX-53M5

Affected Products

Cakephp