CVE-2026-23643
MediumMedium RiskPatchedCakePHP PaginatorHelper XSS
CVSS Score
5.4
Severity
MediumAvailable Package Updates
Fixed in: cakephp/cakephp (Packagist): 5.2.12
Exploit Intelligence
Weaponized
No
Detectable
Yes
CISA KEV
Not Listed
Risk Level
Medium RiskDetection Sources
osv
Get the Full Explanation
Sign in to get the plain English explanation including what systems are affected, how to fix it, and vendor advisory links.
Published: 1/16/2026