Sploitus Critical SQL Injection Vulnerabilities in CakePHP Disclosed
Article Content
- •CVE-2026-79752 and CVE-2026-77635 are critical SQL injection vulnerabilities in CakePHP.
- •Both vulnerabilities have a CVSS score of 9.2, indicating significant risk.
- •Users must upgrade to the latest versions to mitigate these vulnerabilities.
Two critical SQL injection vulnerabilities affecting CakePHP have been disclosed. CVE-2026-79752 allows SQL injection through user-controlled parameters in FunctionsBuilder prior to versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7. CVE-2026-77635 affects FunctionsBuilder::jsonValue() with PostgresDriver, also allowing SQL injection when user-controlled data is supplied to the jsonPath parameter, impacting versions prior to 5.1.10, 5.2.15, and 5.3.7. Both vulnerabilities have a CVSS score of 9.2, indicating critical severity. The vulnerabilities can lead to confidentiality, integrity, and availability impacts based on database connection privileges. Users are advised to update to the fixed versions immediately. The vulnerabilities were published on 2026-09-17 and 2026-08-24, respectively.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-77635 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…