PHP Remote File Inclusion Affecting cakephp/cakephp package, versions <4.5.11>=4.6.0, <4.6.4>=5.0.0, <5.1.7>=5.2.0, <5.2.13>=5.3.0, <5.3.6


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-CAKEPHPCAKEPHP-17420475
  • published23 Jun 2026
  • disclosed18 Jun 2026
  • creditDanh Quan,Tạ Quốc Hùng

Introduced: 18 Jun 2026

CVE-2026-48820  (opens in a new tab)
CWE-98  (opens in a new tab)

How to fix?

Upgrade cakephp/cakephp to version 4.5.11, 4.6.4, 5.1.7, 5.2.13, 5.3.6 or higher.

Overview

cakephp/cakephp is a rapid development framework for PHP which uses commonly known design patterns like Associative Data Mapping, Front Controller, and MVC.

Affected versions of this package are vulnerable to PHP Remote File Inclusion in the View::_getElementFileName() method, which does not verify that the resolved element path stays within the application or plugin view template directories. An attacker can include and execute other PHP files present on the server by placing directory traversal sequences in an element name. Exposure of files by inclusion is limited to PHP files already reachable on the filesystem.

CVSS Base Scores

version 4.0
version 3.1