cakephp/database
Packagist3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cakephp/databasepage 1 of 1
- CVE-2023-22727CRITICALCVSS 9.8EG 9.8fixed in 4.2.12, 4.3.11 or 4.4.10, by version range2023-01-17
vulnerable: 4.4.0 ... 4.4.9 (10 versions)
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue h…
- CVE-2026-77635CRITICALCVSS 9.2EG 9.2fixed in 5.3.7, 5.2.15 or 5.1.10, by version range2026-08-24
vulnerable: 5.1.0 ... 5.1.9 (8 versions)
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is …
- CVE-2026-79752CRITICALCVSS 9.2EG 9.2fixed in 4.5.12, 4.6.5, 5.1.9, 5.2.14 or 5.3.7, by version range2026-09-17
vulnerable: 5.3.0 ... 5.3.6 (6 versions)
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuild…
Check whether cakephp/database is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cakephp/database CVEs against the assets you own.
Book a Demo →