CVE-2019-11458: Cakephp

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.

Affected products

  • Cakephp Cakephp: version 3.7.6 only

Published 2019-05-08. Last modified 2026-06-17.