Vulnerability GHSA-vjqc-q4mp-2rvf
Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
10 days ago
September 17, 2026 at 08:28 PM UTC
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
2.4.5 - 2.4.10 and 2.5.0 - 2.5.9 and 2.6.0 - 2.6.13 and 2.7.0 - 2.7.11 and 2.8.0 - 2.8.9 and 2.9.0 - 2.9.9 and 2.10.0 - 2.10.24 and 3.0.0 - 3.0.19 and 3.1.0 - 3.1.14 and 3.2.0 - 3.2.14 and 3.3.0 - 3.3.16 and 3.4.0 - 3.4.14 and 3.5.0 - 3.5.18 and 3.6.0 - 3.6.15 and 3.7.0 - 3.7.9 and 3.8.0 - 3.8.13 and 3.9.0 - 3.9.10 and 3.10.0 - 3.10.5 and 4.0.0 - 4.0.10 and 4.1.0 - 4.1.7 and 4.2.0 - 4.2.12 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.18 and 4.5.0 - 4.5.11 and 4.6.0 - 4.6.4 and 5.0.0 - 5.0.11 and 5.1.0 - 5.1.8 and 5.2.0 - 5.2.13 and 5.3.0 - 5.3.6
2.4.5 - 2.4.10 and 2.5.0 - 2.5.9 and 2.6.0 - 2.6.13 and 2.7.0 - 2.7.11 and 2.8.0 - 2.8.9 and 2.9.0 - 2.9.9 and 2.10.0 - 2.10.24 and 3.0.0 - 3.0.19 and 3.1.0 - 3.1.14 and 3.2.0 - 3.2.14 and 3.3.0 - 3.3.16 and 3.4.0 - 3.4.14 and 3.5.0 - 3.5.18 and 3.6.0 - 3.6.15 and 3.7.0 - 3.7.9 and 3.8.0 - 3.8.13 and 3.9.0 - 3.9.10 and 3.10.0 - 3.10.5 and 4.0.0 - 4.0.10 and 4.1.0 - 4.1.7 and 4.2.0 - 4.2.12 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.18 and 4.5.0 - 4.5.11 and 4.6.0 - 4.6.4 and 5.0.0 - 5.0.11 and 5.1.0 - 5.1.8 and 5.2.0 - 5.2.13 and 5.3.0 - 5.3.6
Summary
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
Details
Impact
The FunctionsBuilder::cast($field, $dataType), extract($part, $expr), datePart($part, $expr), dateAdd($expr, $value, $unit) methods are vulnerable to SQL injection if user controlled data is supplied to the ($dataType / $part / $unit) parameters.
Patches
5.3.7, 5.2.14, 5.1.9, 4.6.5, 4.5.12 contain fixes
Workarounds
Don't provide user controlled data to these functions/parameters.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
19 days ago
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
5.1.0 - 5.1.9 and 5.2.0 - 5.2.14 and 5.3.0 - 5.3.6 GHSA-fxf7-vhh8-7vpq
5.1.0 - 5.1.9 and 5.2.0 - 5.2.14 and 5.3.0 - 5.3.6 GHSA-fxf7-vhh8-7vpq
Critical
19 days ago
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
5.1.0 - 5.1.9 and 5.2.0 - 5.2.14 and 5.3.0 - 5.3.6 GHSA-fxf7-vhh8-7vpq
5.1.0 - 5.1.9 and 5.2.0 - 5.2.14 and 5.3.0 - 5.3.6 GHSA-fxf7-vhh8-7vpq
High Risk
19 days ago
CakePHP: SmtpTransport vulnerable to CRLF header injection
4.5.0 - 4.5.11 and 4.6.0 - 4.6.4 and 5.0.0 - 5.0.11 and 5.1.0 - 5.1.8 and 5.2.0 - 5.2.13 and 5.3.0 - 5.3.6 GHSA-2qh5-382h-3jpc
4.5.0 - 4.5.11 and 4.6.0 - 4.6.4 and 5.0.0 - 5.0.11 and 5.1.0 - 5.1.8 and 5.2.0 - 5.2.13 and 5.3.0 - 5.3.6 GHSA-2qh5-382h-3jpc
Medium Risk
3 months ago
CakePHP: View::element() is missing a path containment check
2.4.5 - 2.4.10 and 2.5.0 - 2.5.9 and 2.6.0 - 2.6.13 and 2.7.0 - 2.7.11 and 2.8.0 - 2.8.9 and 2.9.0 - 2.9.9 and 2.10.0 - 2.10.24 and 3.0.0 - 3.0.19 and 3.1.0 - 3.1.14 and 3.2.0 - 3.2.14 and 3.3.0 - 3.3.16 and 3.4.0 - 3.4.14 and 3.5.0 - 3.5.18 and 3.6.0 - 3.6.15 and 3.7.0 - 3.7.9 and 3.8.0 - 3.8.13 and 3.9.0 - 3.9.10 and 3.10.0 - 3.10.5 and 4.0.0 - 4.0.10 and 4.1.0 - 4.1.7 and 4.2.0 - 4.2.12 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.18 and 4.5.0 - 4.5.10 and 4.6.0 - 4.6.3 and 5.0.0 - 5.0.11 and 5.1.0 - 5.1.6 and 5.2.0 - 5.2.12 and 5.3.0 - 5.3.5 GHSA-wpvj-hjcr-h3p2
2.4.5 - 2.4.10 and 2.5.0 - 2.5.9 and 2.6.0 - 2.6.13 and 2.7.0 - 2.7.11 and 2.8.0 - 2.8.9 and 2.9.0 - 2.9.9 and 2.10.0 - 2.10.24 and 3.0.0 - 3.0.19 and 3.1.0 - 3.1.14 and 3.2.0 - 3.2.14 and 3.3.0 - 3.3.16 and 3.4.0 - 3.4.14 and 3.5.0 - 3.5.18 and 3.6.0 - 3.6.15 and 3.7.0 - 3.7.9 and 3.8.0 - 3.8.13 and 3.9.0 - 3.9.10 and 3.10.0 - 3.10.5 and 4.0.0 - 4.0.10 and 4.1.0 - 4.1.7 and 4.2.0 - 4.2.12 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.18 and 4.5.0 - 4.5.10 and 4.6.0 - 4.6.3 and 5.0.0 - 5.0.11 and 5.1.0 - 5.1.6 and 5.2.0 - 5.2.12 and 5.3.0 - 5.3.5 GHSA-wpvj-hjcr-h3p2
Medium Risk
8 months ago
CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting
5.2.10 - 5.2.11 and 5.3.0 GHSA-qh8m-9qxx-53m5
5.2.10 - 5.2.11 and 5.3.0 GHSA-qh8m-9qxx-53m5
Impacted packages
Timeline
Published
10 days ago
September 17, 2026 at 08:28 PM UTC
Fixed (4.6.5)
2 months ago
July 03, 2026 at 08:53 PM UTC
Fixed (5.3.7)
2 months ago
July 09, 2026 at 03:06 AM UTC
Fixed (5.3.7)
2 months ago
July 14, 2026 at 03:04 AM UTC
Fixed (5.1.9)
2 months ago
July 14, 2026 at 03:19 AM UTC
Fixed (5.2.14)
2 months ago
July 14, 2026 at 03:43 AM UTC
Fixed (5.2.14)
2 months ago
July 14, 2026 at 03:48 AM UTC
Fixed (4.6.5)
2 months ago
July 15, 2026 at 03:30 AM UTC
Fixed (4.5.12)
2 months ago
July 15, 2026 at 03:38 AM UTC
Fixed (4.5.12)
2 months ago
July 15, 2026 at 03:39 AM UTC
Fixed (5.1.9)
2 months ago
July 16, 2026 at 03:34 AM UTC
Last Modified
3 days ago
September 24, 2026 at 02:45 PM UTC