An open index of dependabot pull requests across open source projects.

cakephp/cakephp

Ecosystem:
packagist
Package URL:
pkg:composer/cakephp/cakephp
Total PRs:
335 Dependabot PRs
Latest PR:
about 1 month ago
Unique Repositories:
83 repositories
Unique Repos (30 days):
2 repositories
Security Advisories
Unsafe deserialization in SmtpTransport in CakePHP
GHSA-qhrx-hcm6-pmrw CVE-2019-11458 HIGH published about 6 years ago • updated 20 days ago
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file over...
CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter
GHSA-556q-h4vr-pgh2 CVE-2015-8379 HIGH published over 3 years ago • updated 7 days ago
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the `_method` parameter.
CakePHP allows remote attackers to spoof their IP
GHSA-j8p3-8m69-2hqq CVE-2016-4793 HIGH published over 3 years ago • updated 6 days ago
The `clientIp` function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the `CLIENT-IP HTTP` header.
CakePHP SecurityComponent cross form submission issue
GHSA-j9q2-f9q7-jhgq MODERATE published almost 3 years ago • updated 2 days ago
Prior to versions 2.4.8 and 1.3.18, forms secured by SecurityComponent could be submitted to any action without triggering SecurityComponent’s tamp...
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file
GHSA-r7p6-fr3x-r877 CVE-2011-3712 MODERATE published over 3 years ago • updated about 2 months ago
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a `.php` file, which reveals the installation path in...
Recent PRs
Package Details
Name: cakephp/cakephp
Ecosystem: packagist
PURL Type: composer
Package URL: pkg:composer/cakephp/cakephp
JSON API: View JSON
Security Advisories

17

Active advisories
CRITICAL 1
HIGH 7
MODERATE 9
View All composer Advisories
Package Information
Description:

The CakePHP framework

Repository: https://github.com/cakephp/cakephp
Homepage: https://cakephp.org
Latest Release: 5.2.3
9 months ago
Dependent Repos: 5,525
Dependent Packages: 1,514
Downloads: 15,696,597
Ranking: Top 0.1245% by dependent repos Top 0.2102% by downloads Top 0.0266% by dependent pkgs
PR Status
Open 94 (28.1%)
Merged 6 (1.8%)
Closed 188 (56.1%)
PR Types
Minor 253 (75.5%)
Patch 35 (10.4%)