VulnSea

cakephp has 7 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 4. The median CVSS is 4.3 (medium), with 2 rated critical. None have a confirmed exploitation report. Most affected products: cakephp/cakephp (3), cakephp (1), cakephp/authentication (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
4.3
Publish → KEV
Last 90 days
6 prev 1

Products

  • cakephp/cakephp 3
  • cakephp 1
  • cakephp/authentication 1
  • cakephp/debug_kit 1
  • cakephp/queue 1
7
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

cakephp vulnerabilities

CVEs affecting cakephp, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-79752Critical· 9.2PoC
5d ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…

Abyssalcakephp · cakephpEPSS 0.46%via NVD
CVE-2026-54713Low· 3.7
3w ago

CakePHP Queue is a queue-interop compatible queueing library

CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting paramet…

Sunlitcakephp · cakephp/queueEPSS 0.36%via NVD
CVE-2026-54614Medium· 4.3
3w ago

DebugKit provides a debugging toolbar for CakePHP applications

DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passe…

Sunlitcakephp · cakephp/debug_kitEPSS 0.31%via NVD
CVE-2026-77635CriticalPoC
4w ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data i…

Abyssalcakephp · cakephp/cakephpEPSS 0.29%via NVD
CVE-2026-77634High
4w ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF…

Twilightcakephp · cakephp/cakephpEPSS 0.31%via NVD
CVE-2026-48820Medium
2mo ago

CakePHP: View::element() is missing a path containment check

CakePHP: View::element() is missing a path containment check

Sunlitcakephp · cakephp/cakephpEPSS 0.26%via GHSA
CVE-2026-55590Medium
3mo ago

CakePHP Authentication: Open redirect weakness via backslash bypass

CakePHP Authentication: Open redirect weakness via backslash bypass

Sunlitcakephp · cakephp/authenticationEPSS 0.49%via GHSA
cakephp vulnerabilities (CVEs) · VulnSea