Frequency
1
occurrences
First Seen
September 19, 2026
Last Seen
September 19, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Two critical SQL injection vulnerabilities affecting CakePHP have been disclosed. CVE-2026-79752 allows SQL injection through user-controlled parameters in FunctionsBuilder prior to versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7. CVE-2026-77635 affects FunctionsBuilder::jsonValue() with PostgresDr...
Public Exploits
Checking GitHub for proof-of-concept code…