These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-54713 is a vulnerability in CakePHP Queue, a queue-interop compatible queueing library. The vulnerability exists in versions 0.1.11 through 2.3.0, where the QueueManager::getUniqueId() method generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters. However, sorting parameter values drops associative-array keys, allowing an unauthenticated attacker to [truncated]
CVE-2026-54614 DebugKit MailPreview feature allows unintended application class selection, leading to arbitrary constructor execution and limited disclosure of application information. This issue affects CakePHP applications using DebugKit, particularly those with debug mode enabled and local or allowlisted request hostnames. The vulnerability enables an attacker to select an unintended application class [truncated]
CVE-2026-77337 debrief based on the supplied source corpus. The CakePHP Authentication plugin has a vulnerability in versions before 2.11.2, 3.3.7, and 4.2.1 that allows authentication bypass and potential CPU or memory exhaustion when using unencrypted, forgeable legacy tokens. This issue affects authentication systems using CakePHP Authentication plugin. Defenders should assess exposure and potential im [truncated]
A critical SQL injection vulnerability exists in CakePHP, a rapid development framework for PHP, prior to versions 5.1.10, 5.2.15, and 5.3.7. The vulnerability is specifically found in the FunctionsBuilder::jsonValue() method when used with the PostgresDriver, and it allows for user-controlled data to be supplied to the jsonPath parameter, potentially leading to SQL injection attacks.
A vulnerability in CakePHP, a rapid development framework for PHP, allows for header injection when user-controlled data is used in message headers. This issue is due to custom mail headers added with Message::setHeaders() or Message::addHeaders() not having CRLF bytes removed. The vulnerability is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.
The CakePHP Authentication plugin has a vulnerability prior to versions 2.11.1, 3.3.6, and 4.1.1. The getLoginRedirect() method contains a weakness to backslash bypasses, allowing redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue affects developers and administrators using the plugin. Patches are available to prevent potential redirects to malicious hostnames.
CVE-2026-48820 is a PHP file inclusion vulnerability in CakePHP View::_getElementFileName(). A patched release is available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, or 4.5.11. This vulnerability allows attackers to include other PHP files on the server by crafting user-supplied data. Developers and administrators should apply patches or mitigations to prevent exploitation.
CVE-2016-4793 is an IP-spoofing flaw in CakePHP’s clientIp() helper. On affected versions, a remote attacker can supply a CLIENT-IP header value that is treated as the client address, which can undermine IP-based security controls and audit data. The NVD record rates the issue HIGH with network access required but no authentication or user interaction.