CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
Published Sep 17, 2026
9.2
CRITICALCVSS 4.0
EPSS 0.62%
Description
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
Affected products
-
- Version < 4.5.12StatusaffectedConstraints-
- Version >= 4.6.0, < 4.6.5StatusaffectedConstraints-
- Version >= 5.0.0, < 5.1.9StatusaffectedConstraints-
- Version >= 5.2.0, < 5.2.14StatusaffectedConstraints-
- Version >= 5.3.0, < 5.3.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 17, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.62% (0.00621) | 47.93th | v5 (v2026.06.15) |
| Sep 18, 2026 | 0.46% (0.00462) | 39.27th | v5 (v2026.06.15) |
References (17)
- https://github.com/advisories/GHSA-vjqc-q4mp-2rvf Advisory
- https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0 x_refsource_MISC
- https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e x_refsource_MISC
- https://github.com/cakephp/cakephp/commit/4730e774bd3b9caa90d67af49e27a12033ec3c71
- https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676 x_refsource_MISC
- https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d x_refsource_MISC
- https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45 x_refsource_MISC
- https://github.com/cakephp/cakephp/pull/19520 x_refsource_MISC
- https://github.com/cakephp/cakephp/pull/19528 x_refsource_MISC
- https://github.com/cakephp/cakephp/releases/tag/4.5.12 x_refsource_MISC
- https://github.com/cakephp/cakephp/releases/tag/4.6.5 x_refsource_MISC
- https://github.com/cakephp/cakephp/releases/tag/5.1.8
- https://github.com/cakephp/cakephp/releases/tag/5.1.9 x_refsource_MISC
- https://github.com/cakephp/cakephp/releases/tag/5.2.14 x_refsource_MISC
- https://github.com/cakephp/cakephp/releases/tag/5.3.7 x_refsource_MISC
- https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-79752
Change history (0)
No recorded changes yet.