The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation.
This issue has been fixed in 5.2.12 and 5.3.1
If you are unable to upgrade, you should avoid using Paginator::limitControl() until you can upgrade.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-01-16T21:00:44Z",
"nvd_published_at": "2026-01-16T21:15:51Z",
"severity": "MODERATE"
}