Critical severityNVD Advisory· Published Sep 17, 2026· Updated Sep 17, 2026
CVE-2026-79752
CVE-2026-79752
Description
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
Affected products
1Patches
Vulnerability mechanics
References
13- github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0nvd
- github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2envd
- github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676nvd
- github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7dnvd
- github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45nvd
- github.com/cakephp/cakephp/pull/19520nvd
- github.com/cakephp/cakephp/pull/19528nvd
- github.com/cakephp/cakephp/releases/tag/4.5.12nvd
- github.com/cakephp/cakephp/releases/tag/4.6.5nvd
- github.com/cakephp/cakephp/releases/tag/5.1.9nvd
- github.com/cakephp/cakephp/releases/tag/5.2.14nvd
- github.com/cakephp/cakephp/releases/tag/5.3.7nvd
- github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvfnvd
News mentions
0No linked articles in our index yet.