CVE-2026-77635EPSS p40.2%
CVE-2026-77635CVE-2026-77635
Description
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
Scoring
| EPSS | 0.49% probability of exploitation · percentile 40.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-09 |