cakephp has 7 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 4. The median CVSS is 4.3 (medium), with 2 rated critical. None have a confirmed exploitation report. Most affected products: cakephp/cakephp (3), cakephp (1), cakephp/authentication (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 1
Weakness classes
Products
- cakephp/cakephp 3
- cakephp 1
- cakephp/authentication 1
- cakephp/debug_kit 1
- cakephp/queue 1
Worst active — by depth score
CVE-2026-77635CriticalCakePHP is a rapid development framework for PHP64CVE-2026-79752Critical· 9.2CakePHP is a rapid development framework for PHP63CVE-2026-77634HighCakePHP is a rapid development framework for PHP41CVE-2026-48820MediumCakePHP: View::element() is missing a path containment check28CVE-2026-55590MediumCakePHP Authentication: Open redirect weakness via backslash bypass28
cakephp vulnerabilities
CVEs affecting cakephp, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-79752Critical· 9.2PoCCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…
CVE-2026-54713Low· 3.7CakePHP Queue is a queue-interop compatible queueing library
CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting paramet…
CVE-2026-54614Medium· 4.3DebugKit provides a debugging toolbar for CakePHP applications
DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passe…
CVE-2026-77635CriticalPoCCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data i…
CVE-2026-77634HighCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF…
CVE-2026-48820MediumCakePHP: View::element() is missing a path containment check
CakePHP: View::element() is missing a path containment check
CVE-2026-55590MediumCakePHP Authentication: Open redirect weakness via backslash bypass
CakePHP Authentication: Open redirect weakness via backslash bypass