All verified exploits

CVE-2026-79752 FunctionsBuilder SQL Injection

Deterministic critical CakePHP Added cve-verified-cve-2026-79752

Detects CakePHP apps whose queries are SQL-injectable through the framework's FunctionsBuilder cast/extract/datePart/dateAdd helpers. In cakephp/database before 5.2.14 / 5.3.7 / 5.1.9 / 4.6.5 / 4.5.12 the data-type, date-part and unit arguments were spliced into the generated SQL as unescaped structural fragments, so an application that forwards request data into any of them is injectable. We prove execution by sending a value like `text)) UNION SELECT 1337*31337-- ` that breaks out of the CAST(...) call and reading the computed product back from the response — data only the database could produce. From there an attacker reads or rewrites the entire database with the connection's privileges. Update cakephp/database to a patched release, which rejects any non-alphanumeric type argument.

Is your app exploitable through CVE-2026-79752?

Scan your domain free