CakePHP 4.4.10 is now available. This release includes bug fixes.
CakePHP 4.4.10 is a rapid development framework for PHP which uses commonly known design patterns like Active Record, Association Data Mapping, Front Controller and MVC. Our primary goal is to provide a structured framework that enables PHP users at all levels to rapidly develop robust web applications, without any loss to flexibility.
CakePHP 4.4.10 Changelog
The CakePHP core team is happy to announce the immediate availability of CakePHP 4.4.10. This release contain a security fix for thelimit()
and offset()
methods of Cake\Database\Query
. If passed unfiltered request data, these methods would allow for SQL injection. If your application does not use CakePHP’s Pagination wrappers and directly passes request data into one of these methods your application is vulnerable. We’d like to thank ‘Tanaka’ for reporting this issue.
🐞 Bug fixes
The 4.4.10 release contains the aforementioned security fix as well as the following fixes.
- Update association definitions in ORM tests.
- Update build images to Ubuntu 22.04.
Although updates are tested, you’re always encouraged to backup your files before patching.
Tags: framework, php framework, Softaculous
Related Links
- Live Demo:
See CakePHP in action (Softaculous site (External link)) - Official Website:
Learn more about CakePHP software (External link) - Run CakePHP in your website:
Please Contact us for more information or start any Hosting Plan and install CakePHP from Softaculous software library