cakephp/cakephp vulnerabilities
CVEs whose affected-version data names the cakephp/cakephp package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-77635CriticalPoCCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data i…
▾ Abyssalcakephp · cakephp/cakephpEPSS 0.29%via NVD
CVE-2026-77634HighCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF…
▾ Twilightcakephp · cakephp/cakephpEPSS 0.31%via NVD
CVE-2026-48820MediumCakePHP: View::element() is missing a path containment check
CakePHP: View::element() is missing a path containment check
▾ Sunlitcakephp · cakephp/cakephpEPSS 0.26%via GHSA