{"schema_version":1,"title":"Cakephp vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in Cakephp: 0 in the last 7 days and 3 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-79752, was published on 17 September 2026.","url":"https://junglewise.ai/threats/technologies/cakephp","json_url":"https://junglewise.ai/threats/technologies/cakephp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/cakephp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":5,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":3,"last_365_days":4},"latest":[{"cve":"CVE-2026-79752","cvss":4,"epss":0.0062,"slug":"cve-2026-79752-cakephp-functionsbuilder-sql-injection-in-multiple-methods","title":"CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder","severity":"critical","exploited":false,"published_at":"2026-09-17T15:16:51.673+00:00","url":"https://junglewise.ai/threats/cve-2026-79752-cakephp-functionsbuilder-sql-injection-in-multiple-methods"},{"cve":"CVE-2026-77635","cvss":4,"epss":0.0049,"slug":"cve-2026-77635-cakephp-functionsbuilder-jsonvalue-sql-injection-with","title":"CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBu","severity":"critical","exploited":false,"published_at":"2026-08-24T21:17:48.457+00:00","url":"https://junglewise.ai/threats/cve-2026-77635-cakephp-functionsbuilder-jsonvalue-sql-injection-with"},{"cve":"CVE-2026-77634","cvss":4,"epss":0.0054,"slug":"cve-2026-77634-cakephp-smtptransport-crlf-header-injection","title":"CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release line","severity":"high","exploited":false,"published_at":"2026-08-24T21:17:48.307+00:00","url":"https://junglewise.ai/threats/cve-2026-77634-cakephp-smtptransport-crlf-header-injection"},{"cve":"CVE-2026-48820","cvss":4,"epss":0.0037,"slug":"cve-2026-48820-cakephp-path-traversal-and-file-inclusion-in-view-component","title":"CakePHP path traversal and file inclusion in View component","severity":"medium","exploited":false,"published_at":"2026-06-17T22:16:22.11+00:00","url":"https://junglewise.ai/threats/cve-2026-48820-cakephp-path-traversal-and-file-inclusion-in-view-component"},{"cve":"CVE-2016-4793","cvss":7.5,"epss":0.0515,"slug":"cve-2016-4793-cakephp-ip-address-spoofing-in-clientip-function","title":"CakePHP IP address spoofing in clientIp function","severity":"high","exploited":false,"published_at":"2017-01-23T21:59:01.58+00:00","url":"https://junglewise.ai/threats/cve-2016-4793-cakephp-ip-address-spoofing-in-clientip-function"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Cakephp","slug":"cakephp","vendor":{"name":"Cakephp","slug":"cakephp","url":"https://junglewise.ai/threats/vendors/cakephp"},"aliases":[],"category":"framework","homepage":"https://cakephp.org","repo_url":"https://github.com/cakephp/cakephp","description":"A web application framework for PHP with rapid development capabilities.","url":"https://junglewise.ai/threats/technologies/cakephp"},"most_severe":[{"cve":"CVE-2026-79752","cvss":4,"epss":0.0062,"slug":"cve-2026-79752-cakephp-functionsbuilder-sql-injection-in-multiple-methods","title":"CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder","severity":"critical","exploited":false,"published_at":"2026-09-17T15:16:51.673+00:00","url":"https://junglewise.ai/threats/cve-2026-79752-cakephp-functionsbuilder-sql-injection-in-multiple-methods"},{"cve":"CVE-2026-77635","cvss":4,"epss":0.0049,"slug":"cve-2026-77635-cakephp-functionsbuilder-jsonvalue-sql-injection-with","title":"CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBu","severity":"critical","exploited":false,"published_at":"2026-08-24T21:17:48.457+00:00","url":"https://junglewise.ai/threats/cve-2026-77635-cakephp-functionsbuilder-jsonvalue-sql-injection-with"},{"cve":"CVE-2016-4793","cvss":7.5,"epss":0.0515,"slug":"cve-2016-4793-cakephp-ip-address-spoofing-in-clientip-function","title":"CakePHP IP address spoofing in clientIp function","severity":"high","exploited":false,"published_at":"2017-01-23T21:59:01.58+00:00","url":"https://junglewise.ai/threats/cve-2016-4793-cakephp-ip-address-spoofing-in-clientip-function"},{"cve":"CVE-2026-77634","cvss":4,"epss":0.0054,"slug":"cve-2026-77634-cakephp-smtptransport-crlf-header-injection","title":"CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release line","severity":"high","exploited":false,"published_at":"2026-08-24T21:17:48.307+00:00","url":"https://junglewise.ai/threats/cve-2026-77634-cakephp-smtptransport-crlf-header-injection"},{"cve":"CVE-2026-48820","cvss":4,"epss":0.0037,"slug":"cve-2026-48820-cakephp-path-traversal-and-file-inclusion-in-view-component","title":"CakePHP path traversal and file inclusion in View component","severity":"medium","exploited":false,"published_at":"2026-06-17T22:16:22.11+00:00","url":"https://junglewise.ai/threats/cve-2026-48820-cakephp-path-traversal-and-file-inclusion-in-view-component"}],"generated_at":"2026-09-26T20:07:00.238639+00:00"}