Cakephp · Cakephp · CVE-2026-48820
**Name of the Vulnerable Software and Affected Versions**
CakePHP versions prior to 4.5.11
CakePHP versions 4.6.0 through 4.6.3
CakePHP versions 5.0.0 through 5.1.6
CakePHP versions 5.2.0 through 5.2.12
CakePHP versions 5.3.0 through 5.3.5
**Description**
The ` getElementFileName()` function in the View class does not verify that the resolved element path remains within the application or plugin view template paths. If element names are constructed using specially crafted user-supplied data, this can be exploited to include arbitrary PHP files from the server.
**Recommendations**
Update to version 4.5.11
Update to version 4.6.4
Update to version 5.1.7
Update to version 5.2.13
Update to version 5.3.6