CVE-2019-8979: Kohanaframework Kohana
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.
Affected products
- Kohanaframework Kohana: up to and including 3.3.6
Published 2019-02-21. Last modified 2026-06-17.