CVE-2026-48820Medium▾ SunlitCakePHP: View::element() is missing a path containment check
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server.
Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
If developers are not using user-supplied data in element names, no action is required.
cakephp/cakephp >= 5.3.0, < 5.3.6cakephp/cakephp >= 5.2.0, < 5.2.13cakephp/cakephp >= 5.0.0, < 5.1.7cakephp/cakephp >= 4.6.0, < 4.6.4cakephp/cakephp < 4.5.11Upgrade to a patched release:
cakephp/cakephp 5.3.6cakephp/cakephp 5.2.13cakephp/cakephp 5.1.7cakephp/cakephp 4.6.4cakephp/cakephp 4.5.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77634HighCakePHP is a rapid development framework for PHP
CVE-2026-77635CriticalCakePHP is a rapid development framework for PHP
CVE-2026-79752Critical· 9.2CakePHP is a rapid development framework for PHP
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4
CVE-2023-7249Critical· 9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.
CVE-2026-54713Low· 3.7CakePHP Queue is a queue-interop compatible queueing library