CVE-2026-23643 - CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scrip...

CVE-2026-23643 - CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scrip...

CVE ID : CVE-2026-23643 Published : Jan. 16, 2026, 9:15 p.m. | 1 hour, 4 minutes ago Description : CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 16, 2026
Affected Product: PHP