CVE-2019-8979: Kohanaframework Kohana

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.

Affected products

Published 2019-02-21. Last modified 2026-06-17.