StackRadar

CVE-2026-79752

Critical

Advisory

Published 17 Sept 2026In the index since 18 Sept 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3
of 18,071 indexed, latest versions
Container images
2
deployed by those charts
Fix available
1 of 1
affected package

CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection

Carried by container images the latest versions of 3 of 18,071 indexed charts deploy, on 2 images.

Affected packageAffected versionsFixed inImages
cakephp/cakephpcomposer4.2.9, 4.3.74.5.122
OSV records
GHSA-vjqc-q4mp-2rvf

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2026-79752.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
cakephp/cakephp@4.2.9
4.5.12

Open the chart page →

5,335
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2026-79752.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
cakephp/cakephp@4.2.9
4.5.12

Open the chart page →

14,137
passboltg0dscookie0.5.21 of 2See more

passbolt g0dscookie 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-79752.

Container imageDigestPackageFixed in
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
cakephp/cakephp@4.3.7
4.5.12

Open the chart page →

10,474

Container images carrying it

2 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
passbolt/passbolt:3.4.0-ce-non-root655547e17263
cakephp/cakephp@4.2.9
4.5.12
2
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
cakephp/cakephp@4.3.7
4.5.12
1

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.