Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 562 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.39% | — | MispAICakephpAI | 22/9/2026 | 22/9/2026 | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: No component of MISP, the vendored CakePHP framework, or any runtime-loaded library reads or… | |
| Aplazada | Media (6.9) | 0.27% | — | MispAICakephpAI | 22/9/2026 | 22/9/2026 | MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because moduleStatelessExecution executes a workflow module's… | |
| Aplazada | Alta (8.7) | 0.64% | — | MispAICakephpAI | 17/9/2026 | 22/9/2026 | MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths() scans the entire argv for path switches (-app, --app, -working,… | |
| Pendiente de análisis | Crítica (9.2) | 0.62% | — | CakephpAI | 17/9/2026 | 30/9/2026 | CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate… | |
| Aplazada | Media (6.9) | 0.20% | — | MispAICakephpAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the normal write verbs POST, PUT, PATCH, and… | |
| Aplazada | Crítica (9.3) | 0.64% | — | MispAICakephpAI | 14/9/2026 | 16/9/2026 | The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the… | |
| Aplazada | Baja (3.7) | 0.46% | — | Cakephp QueueAI | 27/8/2026 | 9/9/2026 | CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can… | |
| Aplazada | Media (4.3) | 0.54% | — | DebugkitAICakephpAI | 26/8/2026 | 9/9/2026 | DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without… | |
| Aplazada | Crítica (9.1) | 0.70% | — | Cakephp AuthenticationAICakephpAI | 24/8/2026 | 9/9/2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy… | |
| Aplazada | Crítica (9.2) | 0.49% | — | CakephpAI | 24/8/2026 | 9/9/2026 | CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10,… | |
| Aplazada | Alta (8.2) | 0.54% | — | CakephpAI | 24/8/2026 | 9/9/2026 | CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in… | |
| Analizada | Media (5.1) | 0.49% | — | Cakephp | 9/7/2026 | 13/7/2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string… | |
| Aplazada | Media (6.3) | 0.37% | — | CakephpAI | 17/6/2026 | 23/6/2026 | CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names… | |
| Analizada | Media (5.4) | 0.29% | — | Cakephp | 16/1/2026 | 17/6/2026 | CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1. | |
| Modificada | Crítica (9.8) | 0.86% | — | Cakephp | 17/1/2023 | 17/6/2026 | CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users… | |
| Modificada | Alta (8.8) | 0.60% | — | Cakephp | 26/1/2021 | 17/6/2026 | A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware… | |
| Modificada | Media (4.3) | 0.45% | — | Cakefoundation Cakephp | 30/6/2020 | 17/6/2026 | CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS. | |
| Modificada | Alta (7.5) | 2.0% | — | Cakephp | 8/5/2019 | 17/6/2026 | An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction. | |
| Modificada | Alta (7.5) | 5.1% | — | Cakephp | 23/1/2017 | 17/6/2026 | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header. | |
| Modificada | Alta (8.8) | 1.4% | — | Cakephp | 26/1/2016 | 17/6/2026 | CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter. | |
| Modificada | Alta (7.5) | 12% | — | Cakefoundation Cakephp | 9/10/2012 | 16/6/2026 | The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack. | |
| Modificada | Media (5) | 1.6% | — | Cakephp | 23/9/2011 | 16/6/2026 | CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files. | |
| Modificada | Alta (7.5) | 55% | — | Cakefoundation CakephpCakephp | 14/1/2011 | 16/6/2026 | The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the… | |
| Modificada | Media (5) | 7.5% | — | Cakephp | 27/9/2006 | 16/6/2026 | Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename. | |
| Modificada | Media (4.3) | 1.2% | — | Cakephp | 10/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information. |