Search
Find merged stories by title or summary.
Vulnerabilities & Patches
Emerging1 src
cve-2026-77635
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
Vulnerabilities & Patches
Emerging1 src
CVE-2026-77635 - CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
CVE ID : CVE-2026-77635 Published : Aug. 24, 2026, 8:30 p. m. • 41 minutes ago Description : CakePHP is a rapid development framework for PHP. Prior to versions 5. 1. 10, 5. 2. 15, and 5. 3. 7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5. 1. 10, 5. 2. 15, and 5. 3. 7. Severity: 0.0 • NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
You've reached the end of current stories for this search.
