CVE-2026-79752 | CakePHP up to 5.3.6 FunctionsBuilder FunctionsBuilder.php dateAdd dataType/part/unit sql injection
A vulnerability labeled as critical has been found in CakePHP up to 4.5.11/4.6.4/5.1.8/5.2.13/5.3.6. The affected element is the function CakePHPDatabaseFunctionsBuilder::cast/CakePHPDatabaseFunctionsBuilder::extract/CakePHPDatabaseFunctionsBuilder::datePart/CakePHPDatabaseFunctionsBuilder::dateAdd of the file src/Database/FunctionsBuilder.php of the component FunctionsBuilder. The manipulation of the argument dataType/part/unit results in sql injection.
This vulnerability is known as CVE-2026-79752. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.VulDB Recent EntriesRead More