CVE-2026-79752
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
| CWE | CWE-89 |
| Vendor | cakephp |
| Product | cakephp |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Get instant alerts for cakephp cakephp
Be the first to know when new unknown vulnerabilities affecting cakephp cakephp are published โ delivered to Slack, Telegram or Discord.