cakephp/database
Flexible and powerful Database abstraction library with a familiar PDO-like API
5.4.1
27M downloads/mo
#827 most downloaded on Packagist
cakephp/database
What this package is like to depend on
Last release 26 days ago
28 Jul 2026
Ships fairly regularly
a new release about every 4 weeks
Rarely documented
notes for 10 of 269 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
336 releases · first in 2015
22 releases in the last 12 months
see the full history below
Release timeline
276 releases · Jan 2015 to Jul 2026Releases
latest 60 of 336-
5.4.128 Jul 2026 -
5.4.019 Jul 2026 -
5.4.0-RC226 Jun 2026 pre-releaseNothing published for this version
-
5.4.0-RC126 Apr 2026 pre-releaseNothing published for this version
-
5.3.709 Jul 2026Release notes
Open source →The postgres driver needs to transforms jsonValue function calls to
rename the function and apply postgres specific cast operations. If the
current implementation is provided a user-controlled path expression,
the generated query can be manipulated.Thanks to Himanshu Anand for reporting this
-
5.3.621 May 2026Nothing published for this version
-
5.3.531 Mar 2026Nothing published for this version
-
5.3.4no dateNothing published for this version
-
5.3.317 Mar 2026Nothing published for this version
-
5.3.224 Feb 2026Nothing published for this version
-
5.3.010 Jan 2026Nothing published for this version
-
5.3.0-RC212 Dec 2025 pre-releaseNothing published for this version
-
5.3.0-RC130 Oct 2025 pre-releaseNothing published for this version
-
5.2.1516 Jul 2026Release notes
Open source →The postgres driver needs to transforms jsonValue function calls to
rename the function and apply postgres specific cast operations. If the
current implementation is provided a user-controlled path expression,
the generated query can be manipulated.Thanks to Himanshu Anand for reporting this
-
5.2.1414 Jul 2026Release notes
Open source →Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.Thank you to Himanshu Anand for reporting this issue.
-
5.2.1316 Nov 2025Nothing published for this version
-
5.2.12no dateNothing published for this version
-
5.2.11no dateNothing published for this version
-
5.2.10no dateNothing published for this version
-
5.2.915 Oct 2025Nothing published for this version
-
5.2.824 Sep 2025Nothing published for this version
-
5.2.727 Aug 2025Nothing published for this version
-
5.2.620 Jul 2025Nothing published for this version
-
5.2.518 Jun 2025Nothing published for this version
-
5.2.409 May 2025Nothing published for this version
-
5.2.322 Apr 2025Nothing published for this version
-
5.2.215 Apr 2025Nothing published for this version
-
5.2.105 Apr 2025Nothing published for this version
-
5.2.025 Mar 2025Nothing published for this version
-
5.2.0-RC123 Feb 2025 pre-releaseNothing published for this version
-
5.1.1016 Jul 2026Release notes
Open source →The postgres driver needs to transforms jsonValue function calls to
rename the function and apply postgres specific cast operations. If the
current implementation is provided a user-controlled path expression,
the generated query can be manipulated.Thanks to Himanshu Anand for reporting this
-
5.1.914 Jul 2026Release notes
Open source →Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.Thank you to Himanshu Anand for reporting this issue.
-
5.1.8no dateRelease notes
Open source →Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.Thank you to Himanshu Anand for reporting this issue.
-
5.1.609 Feb 2025Nothing published for this version
-
5.1.515 Jan 2025Nothing published for this version
-
5.1.412 Dec 2024Nothing published for this version
-
5.1.202 Nov 2024Nothing published for this version
-
5.1.103 Oct 2024Nothing published for this version
-
5.1.012 Sep 2024Nothing published for this version
-
5.1.0-RC207 Aug 2024 pre-releaseNothing published for this version
-
5.1.0-RC120 May 2024 pre-releaseNothing published for this version
-
5.0.1129 Aug 2024Nothing published for this version
-
5.0.1008 Jun 2024Nothing published for this version
-
5.0.9no dateNothing published for this version
-
5.0.819 Apr 2024Nothing published for this version
-
5.0.704 Mar 2024Nothing published for this version
-
5.0.6no dateNothing published for this version
-
5.0.527 Jan 2024Nothing published for this version
-
5.0.426 Dec 2023Nothing published for this version
-
5.0.328 Nov 2023Nothing published for this version
-
5.0.229 Oct 2023Nothing published for this version
-
5.0.010 Sep 2023Nothing published for this version
-
5.0.0-beta203 Apr 2023 pre-releaseNothing published for this version
-
5.0.0-beta101 Dec 2022 pre-releaseNothing published for this version
-
5.0.0-RC211 Jul 2023 pre-releaseNothing published for this version
-
5.0.0-RC103 Jun 2023 pre-releaseNothing published for this version
-
4.6.503 Jul 2026Release notes
Open source →Fix parameter handling in FunctionsBuilder (#19520)
Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.Thank you to Himanshu Anand for reporting this issue.
Backport #19520 to 4.x
-
4.6.330 Oct 2025Nothing published for this version
-
4.6.201 Apr 2025Nothing published for this version
-
4.6.1no dateNothing published for this version