Search
Find a vulnerability
Search criteria
10 vulnerabilities by cakephp
CVE-2026-79752 (GCVE-0-2026-79752)
Vulnerability from cvelistv5 – Published: 2026-09-17 14:49 – Updated: 2026-09-17 15:20
VLAI
EPSS
VEX
Title
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
Summary
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 15:19 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
13 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/cakephp/security/advis… | x_refsource_CONFIRM |
| https://github.com/cakephp/cakephp/pull/19520 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/pull/19528 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/3349584… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/3f4d13e… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/79e1d6b… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/8699d6f… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/ab60871… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/4.5.12 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/4.6.5 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.1.9 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.2.14 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.3.7 | x_refsource_MISC |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-79752",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T15:19:49.116379Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T15:20:00.313Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cakephp",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003c 4.5.12"
},
{
"status": "affected",
"version": "\u003e= 4.6.0, \u003c 4.6.5"
},
{
"status": "affected",
"version": "\u003e= 5.0.0, \u003c 5.1.9"
},
{
"status": "affected",
"version": "\u003e= 5.2.0, \u003c 5.2.14"
},
{
"status": "affected",
"version": "\u003e= 5.3.0, \u003c 5.3.7"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection\u0027s privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T14:49:56.936Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf"
},
{
"name": "https://github.com/cakephp/cakephp/pull/19520",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/pull/19520"
},
{
"name": "https://github.com/cakephp/cakephp/pull/19528",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/pull/19528"
},
{
"name": "https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0"
},
{
"name": "https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e"
},
{
"name": "https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676"
},
{
"name": "https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d"
},
{
"name": "https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/4.5.12",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/4.5.12"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/4.6.5",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/4.6.5"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.1.9",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.1.9"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.2.14",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.2.14"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.3.7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.3.7"
}
],
"source": {
"advisory": "GHSA-vjqc-q4mp-2rvf",
"discovery": "UNKNOWN"
},
"title": "CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-79752",
"datePublished": "2026-09-17T14:49:56.936Z",
"dateReserved": "2026-08-25T14:08:18.109Z",
"dateUpdated": "2026-09-17T15:20:00.313Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-54713 (GCVE-0-2026-54713)
Vulnerability from cvelistv5 – Published: 2026-08-27 17:03 – Updated: 2026-08-28 15:55
VLAI
EPSS
VEX
Title
CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
Summary
CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can influence job parameters can submit semantically different data that produces the same identifier, resulting in legitimate jobs dropped as duplicate collisions. This issue is fixed in version 2.3.1.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-28 15:55 UTC
CWE
- CWE-1023 - Incomplete Comparison with Missing Factors
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/queue/security/advisor… | x_refsource_CONFIRM |
| https://github.com/cakephp/queue/pull/188 | x_refsource_MISC |
| https://github.com/cakephp/queue/commit/13890591e… | x_refsource_MISC |
| https://github.com/cakephp/queue/releases/tag/2.3.1 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-54713",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-28T15:55:07.774512Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T15:55:52.105Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "queue",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003e= 0.1.11, \u003c 2.3.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can influence job parameters can submit semantically different data that produces the same identifier, resulting in legitimate jobs dropped as duplicate collisions. This issue is fixed in version 2.3.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1023",
"description": "CWE-1023: Incomplete Comparison with Missing Factors",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:03:31.580Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/queue/security/advisories/GHSA-r5pm-vrc5-3m73",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/queue/security/advisories/GHSA-r5pm-vrc5-3m73"
},
{
"name": "https://github.com/cakephp/queue/pull/188",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/queue/pull/188"
},
{
"name": "https://github.com/cakephp/queue/commit/13890591e248acc8824becb24ba1939fa061bd34",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/queue/commit/13890591e248acc8824becb24ba1939fa061bd34"
},
{
"name": "https://github.com/cakephp/queue/releases/tag/2.3.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/queue/releases/tag/2.3.1"
}
],
"source": {
"advisory": "GHSA-r5pm-vrc5-3m73",
"discovery": "UNKNOWN"
},
"title": "CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-54713",
"datePublished": "2026-08-27T17:03:31.580Z",
"dateReserved": "2026-06-15T22:58:06.563Z",
"dateUpdated": "2026-08-28T15:55:52.105Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-54614 (GCVE-0-2026-54614)
Vulnerability from cvelistv5 – Published: 2026-08-26 15:30 – Updated: 2026-08-29 02:40
VLAI
EPSS
VEX
Title
DebugKit: MailPreview contains unsafe reflection
Summary
DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without rejecting namespace separators or verifying that the class extends DebugKit\Mailer\MailPreview. An attacker able to access DebugKit while debug mode is enabled and the request hostname is local or allowlisted can select an unintended application class through the mail-preview preview route, resulting in arbitrary constructor execution and limited disclosure of application information. This issue is fixed in versions 4.10.3 and 5.2.4.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-29 02:39 UTC
CWE
- CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/debug_kit/security/adv… | x_refsource_CONFIRM |
| https://github.com/cakephp/debug_kit/pull/1078 | x_refsource_MISC |
| https://github.com/cakephp/debug_kit/commit/7c4d8… | x_refsource_MISC |
| https://github.com/cakephp/debug_kit/commit/c8a2a… | x_refsource_MISC |
| https://github.com/cakephp/debug_kit/releases/tag… | x_refsource_MISC |
| https://github.com/cakephp/debug_kit/releases/tag/5.2.4 | x_refsource_MISC |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-54614",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-29T02:39:54.252351Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T02:40:09.901Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "debug_kit",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003c 4.10.3"
},
{
"status": "affected",
"version": "\u003e= 5.0.0, \u003c 5.2.4"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without rejecting namespace separators or verifying that the class extends DebugKit\\Mailer\\MailPreview. An attacker able to access DebugKit while debug mode is enabled and the request hostname is local or allowlisted can select an unintended application class through the mail-preview preview route, resulting in arbitrary constructor execution and limited disclosure of application information. This issue is fixed in versions 4.10.3 and 5.2.4."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-470",
"description": "CWE-470: Use of Externally-Controlled Input to Select Classes or Code (\u0027Unsafe Reflection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T15:30:23.966Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/debug_kit/security/advisories/GHSA-p46m-g734-vpc4",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/debug_kit/security/advisories/GHSA-p46m-g734-vpc4"
},
{
"name": "https://github.com/cakephp/debug_kit/pull/1078",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/debug_kit/pull/1078"
},
{
"name": "https://github.com/cakephp/debug_kit/commit/7c4d85e984c2334b0f50cd02578a927ff9649e13",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/debug_kit/commit/7c4d85e984c2334b0f50cd02578a927ff9649e13"
},
{
"name": "https://github.com/cakephp/debug_kit/commit/c8a2a9e07d56a5e212d95f6947f370f3b5e6eed6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/debug_kit/commit/c8a2a9e07d56a5e212d95f6947f370f3b5e6eed6"
},
{
"name": "https://github.com/cakephp/debug_kit/releases/tag/4.10.3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/debug_kit/releases/tag/4.10.3"
},
{
"name": "https://github.com/cakephp/debug_kit/releases/tag/5.2.4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/debug_kit/releases/tag/5.2.4"
}
],
"source": {
"advisory": "GHSA-p46m-g734-vpc4",
"discovery": "UNKNOWN"
},
"title": "DebugKit: MailPreview contains unsafe reflection"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-54614",
"datePublished": "2026-08-26T15:30:23.966Z",
"dateReserved": "2026-06-15T19:45:23.541Z",
"dateUpdated": "2026-08-29T02:40:09.901Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77337 (GCVE-0-2026-77337)
Vulnerability from cvelistv5 – Published: 2026-08-24 21:30 – Updated: 2026-08-25 19:23
VLAI
EPSS
VEX
Title
CakePHP: Potential Authentication bypass with CookieAuthenticator
Summary
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 18:32 UTC
CWE
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/authentication/securit… | x_refsource_CONFIRM |
| https://github.com/cakephp/authentication/pull/806 | x_refsource_MISC |
| https://github.com/cakephp/authentication/pull/807 | x_refsource_MISC |
| https://github.com/cakephp/authentication/commit/… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| cakephp | authentication |
Affected:
< 2.11.2
Affected: >= 3.0.0, < 3.3.7 Affected: >= 4.0.0, < 4.2.1 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77337",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:32:35.314141Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T19:23:34.125Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "authentication",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003c 2.11.2"
},
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.3.7"
},
{
"status": "affected",
"version": "\u003e= 4.0.0, \u003c 4.2.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-290",
"description": "CWE-290: Authentication Bypass by Spoofing",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770: Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T21:30:06.817Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37"
},
{
"name": "https://github.com/cakephp/authentication/pull/806",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/pull/806"
},
{
"name": "https://github.com/cakephp/authentication/pull/807",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/pull/807"
},
{
"name": "https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159"
}
],
"source": {
"advisory": "GHSA-h7xh-9h2x-2m37",
"discovery": "UNKNOWN"
},
"title": "CakePHP: Potential Authentication bypass with CookieAuthenticator"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77337",
"datePublished": "2026-08-24T21:30:06.817Z",
"dateReserved": "2026-08-20T19:24:11.618Z",
"dateUpdated": "2026-08-25T19:23:34.125Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77634 (GCVE-0-2026-77634)
Vulnerability from cvelistv5 – Published: 2026-08-24 20:33 – Updated: 2026-08-25 19:23
VLAI
EPSS
VEX
Title
CakePHP: SmtpTransport vulnerable to CRLF header injection
Summary
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 18:32 UTC
CWE
- CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/cakephp/security/advis… | x_refsource_CONFIRM |
| https://github.com/cakephp/cakephp/commit/0818896… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/2afe42b… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/3e09dae… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/b67b622… | x_refsource_MISC |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77634",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:32:29.994179Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T19:23:40.053Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cakephp",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003e= 4.5.0, \u003c 4.5.12"
},
{
"status": "affected",
"version": "\u003e= 4.6.0, \u003c 4.6.5"
},
{
"status": "affected",
"version": "\u003e= 5.0.0, \u003c 5.1.9"
},
{
"status": "affected",
"version": "\u003e= 5.2.0, \u003c 5.2.14"
},
{
"status": "affected",
"version": "\u003e= 5.3.0, \u003c 5.3.7"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-93",
"description": "CWE-93: Improper Neutralization of CRLF Sequences (\u0027CRLF Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T20:33:46.836Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-2qh5-382h-3jpc",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-2qh5-382h-3jpc"
},
{
"name": "https://github.com/cakephp/cakephp/commit/08188962bcd99a95da1e49f62e786f2d688f1e41",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/08188962bcd99a95da1e49f62e786f2d688f1e41"
},
{
"name": "https://github.com/cakephp/cakephp/commit/2afe42b02d8ddc5d442bca5e8bb61910a727646e",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/2afe42b02d8ddc5d442bca5e8bb61910a727646e"
},
{
"name": "https://github.com/cakephp/cakephp/commit/3e09dae6cbdc983754fa3a8e6aae74da102a3ea1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/3e09dae6cbdc983754fa3a8e6aae74da102a3ea1"
},
{
"name": "https://github.com/cakephp/cakephp/commit/b67b622457362b075bb37e625a82af73a0b3c9c3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/b67b622457362b075bb37e625a82af73a0b3c9c3"
}
],
"source": {
"advisory": "GHSA-2qh5-382h-3jpc",
"discovery": "UNKNOWN"
},
"title": "CakePHP: SmtpTransport vulnerable to CRLF header injection"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77634",
"datePublished": "2026-08-24T20:33:46.836Z",
"dateReserved": "2026-08-20T20:52:01.927Z",
"dateUpdated": "2026-08-25T19:23:40.053Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77635 (GCVE-0-2026-77635)
Vulnerability from cvelistv5 – Published: 2026-08-24 20:30 – Updated: 2026-08-25 13:31
VLAI
EPSS
VEX
Title
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
Summary
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 13:31 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/cakephp/security/advis… | x_refsource_CONFIRM |
| https://github.com/cakephp/cakephp/commit/138f2f6… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/489a40f… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/9f1ad97… | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.1.10 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.2.15 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.3.7 | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| cakephp | cakephp |
Affected:
>= 5.1.0, < 5.1.10
Affected: >= 5.2.0, < 5.2.15 Affected: >= 5.3.0, < 5.3.7 |
|
| cakephp | cakephp/database |
Affected:
>= 5.1.0, < 5.1.10
Affected: >= 5.2.0, < 5.2.15 Affected: >= 5.3.0, < 5.3.7 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77635",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T13:31:32.774379Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T13:31:40.225Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cakephp",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003e= 5.1.0, \u003c 5.1.10"
},
{
"status": "affected",
"version": "\u003e= 5.2.0, \u003c 5.2.15"
},
{
"status": "affected",
"version": "\u003e= 5.3.0, \u003c 5.3.7"
}
]
},
{
"product": "cakephp/database",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003e= 5.1.0, \u003c 5.1.10"
},
{
"status": "affected",
"version": "\u003e= 5.2.0, \u003c 5.2.15"
},
{
"status": "affected",
"version": "\u003e= 5.3.0, \u003c 5.3.7"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T20:30:34.492Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq"
},
{
"name": "https://github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3"
},
{
"name": "https://github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55"
},
{
"name": "https://github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.1.10",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.1.10"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.2.15",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.2.15"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.3.7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.3.7"
}
],
"source": {
"advisory": "GHSA-fxf7-vhh8-7vpq",
"discovery": "UNKNOWN"
},
"title": "CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77635",
"datePublished": "2026-08-24T20:30:34.492Z",
"dateReserved": "2026-08-20T20:52:01.928Z",
"dateUpdated": "2026-08-25T13:31:40.225Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-55590 (GCVE-0-2026-55590)
Vulnerability from cvelistv5 – Published: 2026-07-09 18:55 – Updated: 2026-07-09 19:18
VLAI
EPSS
VEX
Title
CakePHP: Open redirect weakness via backslash bypass
Summary
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-09 19:18 UTC
CWE
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Assigner
References
10 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/authentication/securit… | x_refsource_CONFIRM |
| https://github.com/cakephp/authentication/pull/795 | x_refsource_MISC |
| https://github.com/cakephp/authentication/pull/796 | x_refsource_MISC |
| https://github.com/cakephp/authentication/pull/799 | x_refsource_MISC |
| https://github.com/cakephp/authentication/commit/… | x_refsource_MISC |
| https://github.com/cakephp/authentication/commit/… | x_refsource_MISC |
| https://github.com/cakephp/authentication/commit/… | x_refsource_MISC |
| https://github.com/cakephp/authentication/release… | x_refsource_MISC |
| https://github.com/cakephp/authentication/release… | x_refsource_MISC |
| https://github.com/cakephp/authentication/release… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| cakephp | authentication |
Affected:
< 2.11.1
Affected: >= 3.0.0, < 3.3.6 Affected: >= 4.0.0, < 4.1.1 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-55590",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-09T19:18:05.336526Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-09T19:18:12.885Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "authentication",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003c 2.11.1"
},
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.3.6"
},
{
"status": "affected",
"version": "\u003e= 4.0.0, \u003c 4.1.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-09T18:55:30.241Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm"
},
{
"name": "https://github.com/cakephp/authentication/pull/795",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/pull/795"
},
{
"name": "https://github.com/cakephp/authentication/pull/796",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/pull/796"
},
{
"name": "https://github.com/cakephp/authentication/pull/799",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/pull/799"
},
{
"name": "https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273"
},
{
"name": "https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d"
},
{
"name": "https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c"
},
{
"name": "https://github.com/cakephp/authentication/releases/tag/2.11.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/releases/tag/2.11.1"
},
{
"name": "https://github.com/cakephp/authentication/releases/tag/3.3.6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/releases/tag/3.3.6"
},
{
"name": "https://github.com/cakephp/authentication/releases/tag/4.1.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/authentication/releases/tag/4.1.1"
}
],
"source": {
"advisory": "GHSA-hhpq-7wg4-36jm",
"discovery": "UNKNOWN"
},
"title": "CakePHP: Open redirect weakness via backslash bypass"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-55590",
"datePublished": "2026-07-09T18:55:30.241Z",
"dateReserved": "2026-06-16T23:18:03.170Z",
"dateUpdated": "2026-07-09T19:18:12.885Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-48820 (GCVE-0-2026-48820)
Vulnerability from cvelistv5 – Published: 2026-06-17 21:19 – Updated: 2026-06-18 13:54
VLAI
EPSS
VEX
Title
CakePHP: View::element() is missing a path containment check
Summary
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-18 13:52 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/cakephp/cakephp/security/advis… | x_refsource_CONFIRM |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-48820",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-18T13:52:33.657255Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-18T13:54:12.069Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cakephp",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003e= 5.3.0, \u003c 5.3.6"
},
{
"status": "affected",
"version": "\u003e= 5.2.0, \u003c 5.2.13"
},
{
"status": "affected",
"version": "\u003e= 5.0.0, \u003c 5.1.7"
},
{
"status": "affected",
"version": "\u003e= 4.6.0, \u003c 4.6.4"
},
{
"status": "affected",
"version": "\u003c 4.5.11"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-98",
"description": "CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-17T21:19:44.238Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-wpvj-hjcr-h3p2",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-wpvj-hjcr-h3p2"
}
],
"source": {
"advisory": "GHSA-wpvj-hjcr-h3p2",
"discovery": "UNKNOWN"
},
"title": "CakePHP: View::element() is missing a path containment check"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-48820",
"datePublished": "2026-06-17T21:19:44.238Z",
"dateReserved": "2026-05-22T20:57:10.977Z",
"dateUpdated": "2026-06-18T13:54:12.069Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23643 (GCVE-0-2026-23643)
Vulnerability from cvelistv5 – Published: 2026-01-16 20:38 – Updated: 2026-01-16 21:21
VLAI
EPSS
VEX
Title
CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting
Summary
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-01-16 21:21 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/cakephp/security/advis… | x_refsource_CONFIRM |
| https://github.com/cakephp/cakephp/issues/19172 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/commit/c842e7f… | x_refsource_MISC |
| https://bakery.cakephp.org/2026/01/14/cakephp_5212.html | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.2.12 | x_refsource_MISC |
| https://github.com/cakephp/cakephp/releases/tag/5.3.1 | x_refsource_MISC |
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-23643",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-16T21:21:32.578620Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-01-16T21:21:56.372Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cakephp",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003e= 5.2.10, \u003c 5.2.12"
},
{
"status": "affected",
"version": "\u003e= 5.3.0, \u003c 5.3.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-01-16T20:38:45.170Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-qh8m-9qxx-53m5",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-qh8m-9qxx-53m5"
},
{
"name": "https://github.com/cakephp/cakephp/issues/19172",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/issues/19172"
},
{
"name": "https://github.com/cakephp/cakephp/commit/c842e7f45d85696e6527d8991dd72f525ced955f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/c842e7f45d85696e6527d8991dd72f525ced955f"
},
{
"name": "https://bakery.cakephp.org/2026/01/14/cakephp_5212.html",
"tags": [
"x_refsource_MISC"
],
"url": "https://bakery.cakephp.org/2026/01/14/cakephp_5212.html"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.2.12",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.2.12"
},
{
"name": "https://github.com/cakephp/cakephp/releases/tag/5.3.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/releases/tag/5.3.1"
}
],
"source": {
"advisory": "GHSA-qh8m-9qxx-53m5",
"discovery": "UNKNOWN"
},
"title": "CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-23643",
"datePublished": "2026-01-16T20:38:45.170Z",
"dateReserved": "2026-01-14T16:08:37.483Z",
"dateUpdated": "2026-01-16T21:21:56.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2023-22727 (GCVE-0-2023-22727)
Vulnerability from cvelistv5 – Published: 2023-01-17 20:41 – Updated: 2025-03-10 21:22
VLAI
EPSS
VEX
Title
Database Query::offset() and limit() vulnerable to SQL injection in cakephp
Summary
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-03-10 20:59 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/cakephp/cakephp/security/advis… | x_refsource_CONFIRM |
| https://github.com/cakephp/cakephp/commit/3f463e7… | x_refsource_MISC |
| https://bakery.cakephp.org/2023/01/06/cakephp_421… | x_refsource_MISC |
Impacted products
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T10:13:50.233Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp",
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp"
},
{
"name": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239"
},
{
"name": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-22727",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-10T20:59:15.575626Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-03-10T21:22:35.657Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "cakephp",
"vendor": "cakephp",
"versions": [
{
"status": "affected",
"version": "\u003e= 4.2.0, \u003c 4.2.12"
},
{
"status": "affected",
"version": "\u003e= 4.3.0, \u003c 4.3.11"
},
{
"status": "affected",
"version": "\u003e= 4.4.0, \u003c 4.4.10"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CakePHP is a development framework for PHP web apps. In affected versions the `Cake\\Database\\Query::limit()` and `Cake\\Database\\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP\u0027s Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-01-17T20:41:10.143Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp"
},
{
"name": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239"
},
{
"name": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html",
"tags": [
"x_refsource_MISC"
],
"url": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html"
}
],
"source": {
"advisory": "GHSA-6g8q-qfpv-57wp",
"discovery": "UNKNOWN"
},
"title": "Database Query::offset() and limit() vulnerable to SQL injection in cakephp"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2023-22727",
"datePublished": "2023-01-17T20:41:10.143Z",
"dateReserved": "2023-01-06T14:21:05.890Z",
"dateUpdated": "2025-03-10T21:22:35.657Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}