Search

Find a vulnerability

Search criteria

    10 vulnerabilities by cakephp

    CVE-2026-79752 (GCVE-0-2026-79752)

    Vulnerability from cvelistv5 – Published: 2026-09-17 14:49 – Updated: 2026-09-17 15:20
    VLAI
    Title
    CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
    Summary
    CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 15:19 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    cakephp cakephp Affected: < 4.5.12
    Affected: >= 4.6.0, < 4.6.5
    Affected: >= 5.0.0, < 5.1.9
    Affected: >= 5.2.0, < 5.2.14
    Affected: >= 5.3.0, < 5.3.7
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79752",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T15:19:49.116379Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T15:20:00.313Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cakephp",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.12"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.6.0, \u003c 4.6.5"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.0.0, \u003c 5.1.9"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.2.0, \u003c 5.2.14"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.3.0, \u003c 5.3.7"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection\u0027s privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T14:49:56.936Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf"
            },
            {
              "name": "https://github.com/cakephp/cakephp/pull/19520",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/pull/19520"
            },
            {
              "name": "https://github.com/cakephp/cakephp/pull/19528",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/pull/19528"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/4.5.12",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/4.5.12"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/4.6.5",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/4.6.5"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.1.9",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.1.9"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.2.14",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.2.14"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.3.7",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.3.7"
            }
          ],
          "source": {
            "advisory": "GHSA-vjqc-q4mp-2rvf",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-79752",
        "datePublished": "2026-09-17T14:49:56.936Z",
        "dateReserved": "2026-08-25T14:08:18.109Z",
        "dateUpdated": "2026-09-17T15:20:00.313Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54713 (GCVE-0-2026-54713)

    Vulnerability from cvelistv5 – Published: 2026-08-27 17:03 – Updated: 2026-08-28 15:55
    VLAI
    Title
    CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
    Summary
    CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can influence job parameters can submit semantically different data that produces the same identifier, resulting in legitimate jobs dropped as duplicate collisions. This issue is fixed in version 2.3.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-28 15:55 UTC
    CWE
    • CWE-1023 - Incomplete Comparison with Missing Factors
    Impacted products
    Vendor Product Version
    cakephp queue Affected: >= 0.1.11, < 2.3.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54713",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-28T15:55:07.774512Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-28T15:55:52.105Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "queue",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 0.1.11, \u003c 2.3.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can influence job parameters can submit semantically different data that produces the same identifier, resulting in legitimate jobs dropped as duplicate collisions. This issue is fixed in version 2.3.1."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1023",
                  "description": "CWE-1023: Incomplete Comparison with Missing Factors",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-27T17:03:31.580Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/queue/security/advisories/GHSA-r5pm-vrc5-3m73",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/queue/security/advisories/GHSA-r5pm-vrc5-3m73"
            },
            {
              "name": "https://github.com/cakephp/queue/pull/188",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/queue/pull/188"
            },
            {
              "name": "https://github.com/cakephp/queue/commit/13890591e248acc8824becb24ba1939fa061bd34",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/queue/commit/13890591e248acc8824becb24ba1939fa061bd34"
            },
            {
              "name": "https://github.com/cakephp/queue/releases/tag/2.3.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/queue/releases/tag/2.3.1"
            }
          ],
          "source": {
            "advisory": "GHSA-r5pm-vrc5-3m73",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54713",
        "datePublished": "2026-08-27T17:03:31.580Z",
        "dateReserved": "2026-06-15T22:58:06.563Z",
        "dateUpdated": "2026-08-28T15:55:52.105Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54614 (GCVE-0-2026-54614)

    Vulnerability from cvelistv5 – Published: 2026-08-26 15:30 – Updated: 2026-08-29 02:40
    VLAI
    Title
    DebugKit: MailPreview contains unsafe reflection
    Summary
    DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without rejecting namespace separators or verifying that the class extends DebugKit\Mailer\MailPreview. An attacker able to access DebugKit while debug mode is enabled and the request hostname is local or allowlisted can select an unintended application class through the mail-preview preview route, resulting in arbitrary constructor execution and limited disclosure of application information. This issue is fixed in versions 4.10.3 and 5.2.4.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-29 02:39 UTC
    CWE
    • CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
    Impacted products
    Vendor Product Version
    cakephp debug_kit Affected: < 4.10.3
    Affected: >= 5.0.0, < 5.2.4
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54614",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-29T02:39:54.252351Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-29T02:40:09.901Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "debug_kit",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.10.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.0.0, \u003c 5.2.4"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without rejecting namespace separators or verifying that the class extends DebugKit\\Mailer\\MailPreview. An attacker able to access DebugKit while debug mode is enabled and the request hostname is local or allowlisted can select an unintended application class through the mail-preview preview route, resulting in arbitrary constructor execution and limited disclosure of application information. This issue is fixed in versions 4.10.3 and 5.2.4."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-470",
                  "description": "CWE-470: Use of Externally-Controlled Input to Select Classes or Code (\u0027Unsafe Reflection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T15:30:23.966Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/debug_kit/security/advisories/GHSA-p46m-g734-vpc4",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/debug_kit/security/advisories/GHSA-p46m-g734-vpc4"
            },
            {
              "name": "https://github.com/cakephp/debug_kit/pull/1078",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/debug_kit/pull/1078"
            },
            {
              "name": "https://github.com/cakephp/debug_kit/commit/7c4d85e984c2334b0f50cd02578a927ff9649e13",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/debug_kit/commit/7c4d85e984c2334b0f50cd02578a927ff9649e13"
            },
            {
              "name": "https://github.com/cakephp/debug_kit/commit/c8a2a9e07d56a5e212d95f6947f370f3b5e6eed6",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/debug_kit/commit/c8a2a9e07d56a5e212d95f6947f370f3b5e6eed6"
            },
            {
              "name": "https://github.com/cakephp/debug_kit/releases/tag/4.10.3",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/debug_kit/releases/tag/4.10.3"
            },
            {
              "name": "https://github.com/cakephp/debug_kit/releases/tag/5.2.4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/debug_kit/releases/tag/5.2.4"
            }
          ],
          "source": {
            "advisory": "GHSA-p46m-g734-vpc4",
            "discovery": "UNKNOWN"
          },
          "title": "DebugKit: MailPreview contains unsafe reflection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54614",
        "datePublished": "2026-08-26T15:30:23.966Z",
        "dateReserved": "2026-06-15T19:45:23.541Z",
        "dateUpdated": "2026-08-29T02:40:09.901Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77337 (GCVE-0-2026-77337)

    Vulnerability from cvelistv5 – Published: 2026-08-24 21:30 – Updated: 2026-08-25 19:23
    VLAI
    Title
    CakePHP: Potential Authentication bypass with CookieAuthenticator
    Summary
    CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-25 18:32 UTC
    CWE
    • CWE-290 - Authentication Bypass by Spoofing
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    cakephp authentication Affected: < 2.11.2
    Affected: >= 3.0.0, < 3.3.7
    Affected: >= 4.0.0, < 4.2.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77337",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-25T18:32:35.314141Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-25T19:23:34.125Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "authentication",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.11.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 3.0.0, \u003c 3.3.7"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.0.0, \u003c 4.2.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-290",
                  "description": "CWE-290: Authentication Bypass by Spoofing",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770: Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-24T21:30:06.817Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37"
            },
            {
              "name": "https://github.com/cakephp/authentication/pull/806",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/pull/806"
            },
            {
              "name": "https://github.com/cakephp/authentication/pull/807",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/pull/807"
            },
            {
              "name": "https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159"
            }
          ],
          "source": {
            "advisory": "GHSA-h7xh-9h2x-2m37",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP: Potential Authentication bypass with CookieAuthenticator"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-77337",
        "datePublished": "2026-08-24T21:30:06.817Z",
        "dateReserved": "2026-08-20T19:24:11.618Z",
        "dateUpdated": "2026-08-25T19:23:34.125Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77634 (GCVE-0-2026-77634)

    Vulnerability from cvelistv5 – Published: 2026-08-24 20:33 – Updated: 2026-08-25 19:23
    VLAI
    Title
    CakePHP: SmtpTransport vulnerable to CRLF header injection
    Summary
    CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-25 18:32 UTC
    CWE
    • CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
    Impacted products
    Vendor Product Version
    cakephp cakephp Affected: >= 4.5.0, < 4.5.12
    Affected: >= 4.6.0, < 4.6.5
    Affected: >= 5.0.0, < 5.1.9
    Affected: >= 5.2.0, < 5.2.14
    Affected: >= 5.3.0, < 5.3.7
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77634",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-25T18:32:29.994179Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-25T19:23:40.053Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cakephp",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 4.5.0, \u003c 4.5.12"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.6.0, \u003c 4.6.5"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.0.0, \u003c 5.1.9"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.2.0, \u003c 5.2.14"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.3.0, \u003c 5.3.7"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-93",
                  "description": "CWE-93: Improper Neutralization of CRLF Sequences (\u0027CRLF Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-24T20:33:46.836Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-2qh5-382h-3jpc",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-2qh5-382h-3jpc"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/08188962bcd99a95da1e49f62e786f2d688f1e41",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/08188962bcd99a95da1e49f62e786f2d688f1e41"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/2afe42b02d8ddc5d442bca5e8bb61910a727646e",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/2afe42b02d8ddc5d442bca5e8bb61910a727646e"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/3e09dae6cbdc983754fa3a8e6aae74da102a3ea1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/3e09dae6cbdc983754fa3a8e6aae74da102a3ea1"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/b67b622457362b075bb37e625a82af73a0b3c9c3",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/b67b622457362b075bb37e625a82af73a0b3c9c3"
            }
          ],
          "source": {
            "advisory": "GHSA-2qh5-382h-3jpc",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP: SmtpTransport vulnerable to CRLF header injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-77634",
        "datePublished": "2026-08-24T20:33:46.836Z",
        "dateReserved": "2026-08-20T20:52:01.927Z",
        "dateUpdated": "2026-08-25T19:23:40.053Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77635 (GCVE-0-2026-77635)

    Vulnerability from cvelistv5 – Published: 2026-08-24 20:30 – Updated: 2026-08-25 13:31
    VLAI
    Title
    CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
    Summary
    CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-25 13:31 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    cakephp cakephp Affected: >= 5.1.0, < 5.1.10
    Affected: >= 5.2.0, < 5.2.15
    Affected: >= 5.3.0, < 5.3.7
    Create a notification for this product.
    cakephp cakephp/database Affected: >= 5.1.0, < 5.1.10
    Affected: >= 5.2.0, < 5.2.15
    Affected: >= 5.3.0, < 5.3.7
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77635",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-25T13:31:32.774379Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-25T13:31:40.225Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cakephp",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 5.1.0, \u003c 5.1.10"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.2.0, \u003c 5.2.15"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.3.0, \u003c 5.3.7"
                }
              ]
            },
            {
              "product": "cakephp/database",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 5.1.0, \u003c 5.1.10"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.2.0, \u003c 5.2.15"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.3.0, \u003c 5.3.7"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-24T20:30:34.492Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.1.10",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.1.10"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.2.15",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.2.15"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.3.7",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.3.7"
            }
          ],
          "source": {
            "advisory": "GHSA-fxf7-vhh8-7vpq",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-77635",
        "datePublished": "2026-08-24T20:30:34.492Z",
        "dateReserved": "2026-08-20T20:52:01.928Z",
        "dateUpdated": "2026-08-25T13:31:40.225Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-55590 (GCVE-0-2026-55590)

    Vulnerability from cvelistv5 – Published: 2026-07-09 18:55 – Updated: 2026-07-09 19:18
    VLAI
    Title
    CakePHP: Open redirect weakness via backslash bypass
    Summary
    CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-09 19:18 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Vendor Product Version
    cakephp authentication Affected: < 2.11.1
    Affected: >= 3.0.0, < 3.3.6
    Affected: >= 4.0.0, < 4.1.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-55590",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-09T19:18:05.336526Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-09T19:18:12.885Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "authentication",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.11.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 3.0.0, \u003c 3.3.6"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.0.0, \u003c 4.1.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "ACTIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-09T18:55:30.241Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm"
            },
            {
              "name": "https://github.com/cakephp/authentication/pull/795",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/pull/795"
            },
            {
              "name": "https://github.com/cakephp/authentication/pull/796",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/pull/796"
            },
            {
              "name": "https://github.com/cakephp/authentication/pull/799",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/pull/799"
            },
            {
              "name": "https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273"
            },
            {
              "name": "https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d"
            },
            {
              "name": "https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c"
            },
            {
              "name": "https://github.com/cakephp/authentication/releases/tag/2.11.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/releases/tag/2.11.1"
            },
            {
              "name": "https://github.com/cakephp/authentication/releases/tag/3.3.6",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/releases/tag/3.3.6"
            },
            {
              "name": "https://github.com/cakephp/authentication/releases/tag/4.1.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/authentication/releases/tag/4.1.1"
            }
          ],
          "source": {
            "advisory": "GHSA-hhpq-7wg4-36jm",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP: Open redirect weakness via backslash bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-55590",
        "datePublished": "2026-07-09T18:55:30.241Z",
        "dateReserved": "2026-06-16T23:18:03.170Z",
        "dateUpdated": "2026-07-09T19:18:12.885Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48820 (GCVE-0-2026-48820)

    Vulnerability from cvelistv5 – Published: 2026-06-17 21:19 – Updated: 2026-06-18 13:54
    VLAI
    Title
    CakePHP: View::element() is missing a path containment check
    Summary
    CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-18 13:52 UTC
    CWE
    • CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    cakephp cakephp Affected: >= 5.3.0, < 5.3.6
    Affected: >= 5.2.0, < 5.2.13
    Affected: >= 5.0.0, < 5.1.7
    Affected: >= 4.6.0, < 4.6.4
    Affected: < 4.5.11
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48820",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-18T13:52:33.657255Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-18T13:54:12.069Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cakephp",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 5.3.0, \u003c 5.3.6"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.2.0, \u003c 5.2.13"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.0.0, \u003c 5.1.7"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.6.0, \u003c 4.6.4"
                },
                {
                  "status": "affected",
                  "version": "\u003c 4.5.11"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-98",
                  "description": "CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-17T21:19:44.238Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-wpvj-hjcr-h3p2",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-wpvj-hjcr-h3p2"
            }
          ],
          "source": {
            "advisory": "GHSA-wpvj-hjcr-h3p2",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP: View::element() is missing a path containment check"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-48820",
        "datePublished": "2026-06-17T21:19:44.238Z",
        "dateReserved": "2026-05-22T20:57:10.977Z",
        "dateUpdated": "2026-06-18T13:54:12.069Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23643 (GCVE-0-2026-23643)

    Vulnerability from cvelistv5 – Published: 2026-01-16 20:38 – Updated: 2026-01-16 21:21
    VLAI
    Title
    CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting
    Summary
    CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-16 21:21 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    cakephp cakephp Affected: >= 5.2.10, < 5.2.12
    Affected: >= 5.3.0, < 5.3.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23643",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-16T21:21:32.578620Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-16T21:21:56.372Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cakephp",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 5.2.10, \u003c 5.2.12"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.3.0, \u003c 5.3.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-16T20:38:45.170Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-qh8m-9qxx-53m5",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-qh8m-9qxx-53m5"
            },
            {
              "name": "https://github.com/cakephp/cakephp/issues/19172",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/issues/19172"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/c842e7f45d85696e6527d8991dd72f525ced955f",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/c842e7f45d85696e6527d8991dd72f525ced955f"
            },
            {
              "name": "https://bakery.cakephp.org/2026/01/14/cakephp_5212.html",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bakery.cakephp.org/2026/01/14/cakephp_5212.html"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.2.12",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.2.12"
            },
            {
              "name": "https://github.com/cakephp/cakephp/releases/tag/5.3.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/releases/tag/5.3.1"
            }
          ],
          "source": {
            "advisory": "GHSA-qh8m-9qxx-53m5",
            "discovery": "UNKNOWN"
          },
          "title": "CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-23643",
        "datePublished": "2026-01-16T20:38:45.170Z",
        "dateReserved": "2026-01-14T16:08:37.483Z",
        "dateUpdated": "2026-01-16T21:21:56.372Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-22727 (GCVE-0-2023-22727)

    Vulnerability from cvelistv5 – Published: 2023-01-17 20:41 – Updated: 2025-03-10 21:22
    VLAI
    Title
    Database Query::offset() and limit() vulnerable to SQL injection in cakephp
    Summary
    CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-10 20:59 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    cakephp cakephp Affected: >= 4.2.0, < 4.2.12
    Affected: >= 4.3.0, < 4.3.11
    Affected: >= 4.4.0, < 4.4.10
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:50.233Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp",
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp"
              },
              {
                "name": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239"
              },
              {
                "name": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22727",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-10T20:59:15.575626Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-10T21:22:35.657Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cakephp",
              "vendor": "cakephp",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 4.2.0, \u003c 4.2.12"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.3.0, \u003c 4.3.11"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.4.0, \u003c 4.4.10"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "CakePHP is a development framework for PHP web apps. In affected versions the `Cake\\Database\\Query::limit()` and `Cake\\Database\\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP\u0027s Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-01-17T20:41:10.143Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp"
            },
            {
              "name": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239"
            },
            {
              "name": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html"
            }
          ],
          "source": {
            "advisory": "GHSA-6g8q-qfpv-57wp",
            "discovery": "UNKNOWN"
          },
          "title": "Database Query::offset() and limit() vulnerable to SQL injection in cakephp"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2023-22727",
        "datePublished": "2023-01-17T20:41:10.143Z",
        "dateReserved": "2023-01-06T14:21:05.890Z",
        "dateUpdated": "2025-03-10T21:22:35.657Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }