Impact
The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation.
Patches
This issue has been fixed in 5.2.12 and 5.3.1
Workarounds
If you are unable to upgrade, you should avoid using Paginator::limitControl() until you can upgrade.
References
https://bakery.cakephp.org/2026/01/14/cakephp_5212.html
Impact
The
PaginatorHelper::limitControl()method has a cross-site-scripting vulnerability via query string parameter manipulation.Patches
This issue has been fixed in 5.2.12 and 5.3.1
Workarounds
If you are unable to upgrade, you should avoid using
Paginator::limitControl()until you can upgrade.References
https://bakery.cakephp.org/2026/01/14/cakephp_5212.html