{"id":"CVE-2026-23643","summary":"CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting","details":"CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.","aliases":["GHSA-qh8m-9qxx-53m5"],"modified":"2026-08-12T03:51:15.939881981Z","published":"2026-01-16T20:38:45.170Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23643.json"},"references":[{"type":"WEB","url":"https://bakery.cakephp.org/2026/01/14/cakephp_5212.html"},{"type":"WEB","url":"https://github.com/cakephp/cakephp/releases/tag/5.2.12"},{"type":"WEB","url":"https://github.com/cakephp/cakephp/releases/tag/5.3.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23643.json"},{"type":"ADVISORY","url":"https://github.com/cakephp/cakephp/security/advisories/GHSA-qh8m-9qxx-53m5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23643"},{"type":"REPORT","url":"https://github.com/cakephp/cakephp/issues/19172"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/commit/c842e7f45d85696e6527d8991dd72f525ced955f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cakephp/cakephp","events":[{"introduced":"7b871bc048c59774c07f283814bf8af9ea88ea27"},{"fixed":"e2cdc8f1c907d204f4bccf76bac1b2b93eea922e"},{"introduced":"c0175d821a5e42b934ad2a11927c5c5d0e659a0d"},{"fixed":"c842e7f45d85696e6527d8991dd72f525ced955f"},{"fixed":"ae91c0950fd1a4ee9b97b31a8db744721cdb9bd0"}],"database_specific":{"extracted_events":[{"introduced":"5.2.10"},{"fixed":"5.2.12"},{"introduced":"5.3.0"},{"last_affected":"5.3.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*","cpe:2.3:a:cakephp:cakephp:5.3.0:*:*:*:*:*:*:*"]}}],"versions":["5.3.0","5.2.11","5.2.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23643.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}