296,147
Total vulnerabilities in the database
CakePHP 3.4 prior to 3.4.14, 3.5 prior to 3.5.17, and 3.6 prior to 3.6.4 contains a cross-site-scripting (XSS) vulnerability in the development only missing route
and duplicate named route
error pages.
Software | From | Fixed in |
---|---|---|
![]() |
3.4.0 | 3.4.14 |
![]() |
3.5.0 | 3.5.17 |
![]() |
3.6.0 | 3.6.4 |