We support fixing security issues on the following releases:
| Version | Supported | Security fixes until |
|---|---|---|
| 5.0 | :white_check_mark: | The release of 5.2 |
| 4.5 | :white_check_mark: | 36 Months after the release of 5.0 (09 Sep 2026) |
| 4.4 | :white_check_mark: | 36 Months after the release of 5.0 (09 Sep 2026) |
| 4.3 | :white_check_mark: | 36 Months after the release of 5.0 (09 Sep 2026) |
| 4.2 | :x: | No longer supported |
| 4.1 | :x: | No longer supported |
| 4.0 | :x: | No longer supported |
| 3.10.x | :x: | No longer supported |
| 2.10.x | :x: | No longer supported |
If you’ve found a security issue in CakePHP, please use the following procedure instead of the normal bug reporting system. Instead of using the bug tracker, or one of the support forums please send an email to security [at] cakephp.org. Emails sent to this address go to the CakePHP core team on a private mailing list.
For each report, we try to first confirm the vulnerability. Once confirmed, the CakePHP team will take the following actions: