CVE-2026-79752: Cakephp
Critical severity, CVSS 9.2. EPSS: 0.6% chance of exploitation in the next 30 days.
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
Affected products
- Cakephp Cakephp: before 4.5.12 (fixed in 4.5.12); from 4.6.0, before 4.6.5 (fixed in 4.6.5); from 5.0.0, before 5.1.9 (fixed in 5.1.9); from 5.2.0, before 5.2.14 (fixed in 5.2.14); from 5.3.0, before 5.3.7 (fixed in 5.3.7)
Published 2026-09-17. Last modified 2026-09-30.