๐Ÿ” CVE Alert

CVE-2026-48820

UNKNOWN 0.0

CakePHP: View::element() is missing a path containment check

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.

CWE CWE-98 CWE-22
Vendor cakephp
Product cakephp
Published Jun 17, 2026
Stay Ahead of the Next One

Get instant alerts for cakephp cakephp

Be the first to know when new unknown vulnerabilities affecting cakephp cakephp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cakephp / cakephp
>= 5.3.0, < 5.3.6 >= 5.2.0, < 5.2.13 >= 5.0.0, < 5.1.7 >= 4.6.0, < 4.6.4 < 4.5.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cakephp/cakephp/security/advisories/GHSA-wpvj-hjcr-h3p2