EN

critical CVE-2026-79752

CakePHP is a rapid development framework for PHP: SQL injection possible

NVD (NIST) reports one vulnerability in CakePHP is a rapid development framework for PHP with severity critical. The stated impact is SQL injection. Affected: CVE-2026-79752. The full description, affected versions and recommended action are available from NVD (NIST).

CVSS
9.2

What this means for you

The application can be used to reach the database behind it. Check the logs before you patch: unusual queries suggest the flaw has already been used.

Original source

NVD (NIST)

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.