CVE-2026-23643: CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting

Published Jan 16, 2026
·
Updated

Impact The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation.

Patches This issue has been fixed in 5.2.12 and 5.3.1

Workarounds If you are unable to upgrade, you should avoid using Paginator::limitControl() until you can upgrade.

Other sources

CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.

MITRE

Affected Software

5 affected componentsFixes available
cakephp/cakephp>=5.2.12<=5.3.1
composer/cakephp/cakephp=5.3.0
5.3.1
composer/cakephp/cakephp>=5.2.10<5.2.12
5.2.12
CakePHP CakePHP>=5.2.10<5.2.12
CakePHP CakePHP=5.3.0

Event History

Jan 16, 2026
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:00 PM
Data Sourced
via GitHub·09:00 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-23643?

CVE-2026-23643 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attack.

2

How do I fix CVE-2026-23643?

To fix CVE-2026-23643, upgrade CakePHP to version 5.2.12 or later.

3

Which versions of CakePHP are affected by CVE-2026-23643?

CVE-2026-23643 affects CakePHP versions between 5.2.12 and 5.3.1 inclusive.

4

What type of vulnerability is CVE-2026-23643?

CVE-2026-23643 is a reflected cross-site scripting (XSS) vulnerability.

5

Is CVE-2026-23643 specific to certain methods in CakePHP?

Yes, CVE-2026-23643 specifically affects the PaginatorHelper::limitControl() method in CakePHP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203