Vulnerabilities > Cakefoundation > Cakephp > 2.1.1

DATE CVE VULNERABILITY TITLE RISK
2020-06-30 CVE-2020-15400 Cross-Site Request Forgery (CSRF) vulnerability in Cakefoundation Cakephp
CakePHP before 4.0.6 mishandles CSRF token generation.
4.3
2012-10-09 CVE-2012-4399 XXE vulnerability in Cakefoundation Cakephp
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
network
low complexity
cakefoundation CWE-611
7.5