An open index of dependabot pull requests across open source projects.

cakephp/cakephp

Ecosystem:
packagist
Package URL:
pkg:composer/cakephp/cakephp
Total PRs:
340 Dependabot PRs
Latest PR:
about 1 month ago
Unique Repositories:
85 repositories
Unique Repos (30 days):
0 repositories
Security Advisories
CakePHP vulnerable to Cross-site Scripting in some development error pages
GHSA-xwhj-pqcg-8rcr MODERATE published about 3 years ago • updated about 24 hours ago
CakePHP 3.4 prior to 3.4.14, 3.5 prior to 3.5.17, and 3.6 prior to 3.6.4 contains a cross-site-scripting (XSS) vulnerability in the development onl...
Cross-Site Request Forgery in CakePHP
GHSA-j33j-fg2g-mcv2 CVE-2020-15400 MODERATE published about 4 years ago • updated about 24 hours ago
CakePHP before 4.0.6 and 3.10.3 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
CakePHP directory traversal vulnerability allows remote attackers to read arbitrary files
GHSA-rw73-xmpv-j5x2 CVE-2006-5031 MODERATE published almost 4 years ago • updated 15 days ago
Directory traversal vulnerability in `app/webroot/js/vendors.php` in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to ...
CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter
GHSA-556q-h4vr-pgh2 CVE-2015-8379 HIGH published almost 4 years ago • updated 15 days ago
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the `_method` parameter.
CakePHP vulnerable to Denial of Service attack through XML payloads
GHSA-q79m-c546-2g63 HIGH published about 3 years ago • updated 3 days ago
RequestHandlerComponent had a vulnerability that would allow well crafted requests to create a denial of service attack. RequestHandlerComponent le...
Recent PRs
Package Details
Name: cakephp/cakephp
Ecosystem: packagist
PURL Type: composer
Package URL: pkg:composer/cakephp/cakephp
JSON API: View JSON
Security Advisories

18

Active advisories
CRITICAL 1
HIGH 7
MODERATE 10
View All composer Advisories
Package Information
Description:

The CakePHP framework

Repository: https://github.com/cakephp/cakephp
Homepage: https://cakephp.org
Latest Release: 5.2.3
10 months ago
Dependent Repos: 5,525
Dependent Packages: 1,514
Downloads: 15,696,597
Ranking: Top 0.1245% by dependent repos Top 0.2102% by downloads Top 0.0266% by dependent pkgs
PR Status
Open 94 (27.6%)
Merged 6 (1.8%)
Closed 193 (56.8%)
PR Types
Minor 255 (75.0%)
Patch 38 (11.2%)